CWE-787
14,715 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,715)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian DigiumFedoraproject5Asterisk AsterisknowDebian Linux+2 moreApr 29, 2026 Jan 20, 2011 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when r...Show more |
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute ar...Show more |
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application cra...Show more |
Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash)...Show more |
Stack-based buffer overflow in the load_preset_response function in plug-ins/lighting/lighting-ui.c in the "LIGHTING EFFECTS > LIGHT" plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of servi...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large n...Show more |
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5....Show more |
5Debian FedoraprojectLinux+2 more7Debian Linux FedoraLinux Enterprise Desktop+4 moreApr 29, 2026 Dec 29, 2010 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow...Show more |
2Debian Linux2Debian Linux Linux KernelApr 29, 2026 Dec 29, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 21, 2026 Dec 6, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows...Show more |
1Microsoft 2Office Open Xml File Format ConverterApr 22, 2026 Nov 10, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers...Show more |
3Fedoraproject GoogleWebkitgtk3Chrome FedoraWebkitgtkApr 29, 2026 Nov 6, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers...Show more |
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (applic...Show more |
4Apple CanonicalDebian+1 more4Debian Linux FreetypeMac Os X+1 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or p...Show more |
4Apple CanonicalDebian+1 more4Debian Linux FreetypeMac Os X+1 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via...Show more |
4Apple CanonicalDebian+1 more4Debian Linux FreetypeMac Os X+1 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and a...Show more |
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy. |
3Adobe OpensuseSuse5Acrobat AirFlash Player+2 moreApr 21, 2026 Jun 8, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute...Show more |