CWE-787
14,750 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,750)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 20Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+17 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. |
1Qualcomm 146Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+143 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. |
1Qualcomm 103215 Mobile Firmware Csra6620 FirmwareCsra6640 Firmware+100 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while reading the FW response from the shared queue. |
1Qualcomm 13Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSa4150p Firmware+10 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit. |
1Qualcomm 36Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+33 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously. |
1Qualcomm 144Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+141 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during the FRS UDS generation process. |
1Qualcomm 179Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+176 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while triggering commands in the PlayReady Trusted application. |
1Qualcomm 207Aqt1000 Firmware Ar8035 FirmwareCsra6620 Firmware+204 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while reading secure file. |
1Qualcomm 30Mdm9628 Firmware Qam8295p FirmwareQca6564a Firmware+27 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while sound model registration for voice activation with audio kernel driver. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+7 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+7 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. |
1Qualcomm 14Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+11 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session. |
Out-of-bounds array read/write vulnerability in the kernel module
Impact: Successful exploitation of this vulnerability may affect availability. |
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML p...Show more |
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed...Show more |
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not need...Show more |
In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eeprom() ice_get_module_eeprom() is broken since commit e9c9692c8a81 ("ice: Reimplement module reads us...Show more |
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption after failed write When buffered write fails to copy data into underlying page cache page, ocfs2_write_end_nolock() just ze...Show more |
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix shift-out-of-bounds in CalculateVMAndRowBytes [WHY] When PTEBufferSizeInRequests is zero, UBSAN reports the following warning bec...Show more |
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix perf_output_begin parameter is incorrectly invoked in perf_event_bpf_output syzkaller reportes a KASAN issue with stack-out-of-bounds....Show more |