CWE-787
14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian LibtiffOpensuse+1 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Mar 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craft...Show more |
4Apple DebianLibtiff+1 more8Debian Linux Enterprise Linux ServerEnterprise Linux Server Aus+5 moreNov 21, 2024 Mar 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the Bit...Show more |
In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attackers could leverage this vulnerability t...Show more |
1Huawei 21Ar120 S Firmware Ar1200 S FirmwareAr1200 Firmware+18 moreNov 21, 2024 Mar 9, 2018 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C...Show more |
GPU driver in Huawei Mate 10 smart phones with the versions before ALP-L09 8.0.0.120(C212); The versions before ALP-L09 8.0.0.127(C900); The versions before ALP-L09 8.0.0.128(402/C02/C109/C346/C432/C652) has a out-of-bou...Show more |
1Huawei 6Dp300 Firmware Rp200 FirmwareTe30 Firmware+3 moreNov 21, 2024 Mar 9, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100...Show more |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Mar 9, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service. |
4Canonical FreebsdNetapp+1 more4Element Software FreebsdNtp+1 moreJun 17, 2026 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. |
2Debian Libming2Debian Linux LibmingJun 17, 2026 Mar 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a denial of service attack. |
2Debian Libming2Debian Linux LibmingJun 17, 2026 Mar 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a denial of service attack. |
2Debian Libming2Debian Linux LibmingJun 17, 2026 Mar 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 during a RegisterNumber sprintf. A Crafted input will lead to a denial of service attack. |
1Emerson 1Controlwave Micro Firmware Jun 17, 2026 Mar 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based...Show more |
2Debian Net Snmp2Debian Linux Net SnmpNov 21, 2024 Mar 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution. |
1Huawei 24Dp300 Firmware Ips Module FirmwareNgfw Module Firmware+21 moreNov 21, 2024 Mar 5, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S1270...Show more |
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value. |
4Canonical DebianQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Mar 1, 2018 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which trig...Show more |
Stack-based Buffer Overflow in httpd on Tenda AC9 devices V15.03.05.14_EN allows remote attackers to cause a denial of service or possibly have unspecified other impact. |
1Activepdf 1Activepdf Toolkit Jun 17, 2026 Feb 28, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable...Show more |
2Debian Sam2p Project2Debian Linux Sam2pJun 17, 2026 Feb 28, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. |
A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d. |