← Back
CWE-787

14,348 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,348)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Jan 24, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
1Adobe
2Acrobat
Reader
Apr 29, 2026
Jan 10, 2012
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnera...Show more
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.Show less
1Adobe
2Acrobat
Reader
Apr 29, 2026
Jan 10, 2012
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnera...Show more
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4373.Show less
1Adobe
2Acrobat
Reader
Apr 29, 2026
Jan 10, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
1Adobe
2Acrobat
Reader
Apr 29, 2026
Jan 10, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnera...Show more
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4372 and CVE-2011-4373.Show less
1Google
1Chrome
Apr 29, 2026
Jan 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.
5Apple
DebianGoogle+2 more
9Chrome
Debian LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Jan 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
7Canonical
DebianFedoraproject+4 more
9Debian Linux
Enterprise Linux DesktopFedora+6 more
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute a...Show more
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.Show less
6Canonical
DebianFedoraproject+3 more
8Debian Linux
FedoraJasper+5 more
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted...Show more
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.Show less
1Google
1Chrome
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in FileWatcher in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The internationalization (aka i18n) functionality in Google V8, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vect...Show more
The internationalization (aka i18n) functionality in Google V8, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.Show less
3F5
FedoraprojectSuse
5Fedora
NginxStudio+2 more
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via...Show more
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 21, 2026
Dec 7, 2011
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or caus...Show more
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.Show less
1Google
1Chrome
Apr 29, 2026
Nov 17, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write operation.
2Apple
Suse
4Iphone Os
Linux Enterprise DesktopLinux Enterprise Server+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
1Google
1Chrome
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
1Google
1Chrome
Apr 29, 2026
Aug 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
3Apple
GimpSwi Prolog
3Cups
GimpSwi Prolog
Apr 29, 2026
Aug 19, 2011
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug...Show more
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.Show less