← Back
CWE-787

14,750 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,750)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
20Fastconnect 6700 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+17 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
1Qualcomm
146Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+143 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
1Qualcomm
103215 Mobile Firmware
Csra6620 FirmwareCsra6640 Firmware+100 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while reading the FW response from the shared queue.
1Qualcomm
13Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSa4150p Firmware+10 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.
1Qualcomm
36Qam8255p Firmware
Qam8295p FirmwareQam8620p Firmware+33 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.
1Qualcomm
144Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+141 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption during the FRS UDS generation process.
1Qualcomm
179Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+176 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while triggering commands in the PlayReady Trusted application.
1Qualcomm
207Aqt1000 Firmware
Ar8035 FirmwareCsra6620 Firmware+204 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while reading secure file.
1Qualcomm
30Mdm9628 Firmware
Qam8295p FirmwareQca6564a Firmware+27 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while sound model registration for voice activation with audio kernel driver.
1Qualcomm
10Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSdm429w Firmware+7 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
1Qualcomm
10Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSdm429w Firmware+7 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
1Qualcomm
14Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSdm429w Firmware+11 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.
1Huawei
1Harmonyos
Jun 17, 2026
May 6, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availability.
1Google
1Chrome
Jun 17, 2026
May 5, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML p...Show more
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Android
Jun 17, 2026
May 5, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed...Show more
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228.Show less
1Google
1Android
Jun 17, 2026
May 5, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not need...Show more
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.Show less
1Linux
1Linux Kernel
Jun 17, 2026
May 2, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eeprom() ice_get_module_eeprom() is broken since commit e9c9692c8a81 ("ice: Reimplement module reads us...Show more
In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eeprom() ice_get_module_eeprom() is broken since commit e9c9692c8a81 ("ice: Reimplement module reads used by ethtool") In this refactor, ice_get_module_eeprom() reads the eeprom in blocks of size 8. But the condition that should protect the buffer overflow ignores the last block. The last block always contains zeros. Bug uncovered by ethtool upstream commit 9538f384b535 ("netlink: eeprom: Defer page requests to individual parsers") After this commit, ethtool reads a block with length = 1; to read the SFF-8024 identifier value. unpatched driver: $ ethtool -m enp65s0f0np0 offset 0x90 length 8 Offset Values ------ ------ 0x0090: 00 00 00 00 00 00 00 00 $ ethtool -m enp65s0f0np0 offset 0x90 length 12 Offset Values ------ ------ 0x0090: 00 00 01 a0 4d 65 6c 6c 00 00 00 00 $ $ ethtool -m enp65s0f0np0 Offset Values ------ ------ 0x0000: 11 06 06 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 01 08 00 0x0070: 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 patched driver: $ ethtool -m enp65s0f0np0 offset 0x90 length 8 Offset Values ------ ------ 0x0090: 00 00 01 a0 4d 65 6c 6c $ ethtool -m enp65s0f0np0 offset 0x90 length 12 Offset Values ------ ------ 0x0090: 00 00 01 a0 4d 65 6c 6c 61 6e 6f 78 $ ethtool -m enp65s0f0np0 Identifier : 0x11 (QSFP28) Extended identifier : 0x00 Extended identifier description : 1.5W max. Power consumption Extended identifier description : No CDR in TX, No CDR in RX Extended identifier description : High Power Class (> 3.5 W) not enabled Connector : 0x23 (No separable connector) Transceiver codes : 0x88 0x00 0x00 0x00 0x00 0x00 0x00 0x00 Transceiver type : 40G Ethernet: 40G Base-CR4 Transceiver type : 25G Ethernet: 25G Base-CR CA-N Encoding : 0x05 (64B/66B) BR, Nominal : 25500Mbps Rate identifier : 0x00 Length (SMF,km) : 0km Length (OM3 50um) : 0m Length (OM2 50um) : 0m Length (OM1 62.5um) : 0m Length (Copper or Active cable) : 1m Transmitter technology : 0xa0 (Copper cable unequalized) Attenuation at 2.5GHz : 4db Attenuation at 5.0GHz : 5db Attenuation at 7.0GHz : 7db Attenuation at 12.9GHz : 10db ........ ....Show less
1Linux
1Linux Kernel
Jun 17, 2026
May 2, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption after failed write When buffered write fails to copy data into underlying page cache page, ocfs2_write_end_nolock() just ze...Show more
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption after failed write When buffered write fails to copy data into underlying page cache page, ocfs2_write_end_nolock() just zeroes out and dirties the page. This can leave dirty page beyond EOF and if page writeback tries to write this page before write succeeds and expands i_size, page gets into inconsistent state where page dirty bit is clear but buffer dirty bits stay set resulting in page data never getting written and so data copied to the page is lost. Fix the problem by invalidating page beyond EOF after failed write.Show less
1Linux
1Linux Kernel
Jun 17, 2026
May 2, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix shift-out-of-bounds in CalculateVMAndRowBytes [WHY] When PTEBufferSizeInRequests is zero, UBSAN reports the following warning bec...Show more
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix shift-out-of-bounds in CalculateVMAndRowBytes [WHY] When PTEBufferSizeInRequests is zero, UBSAN reports the following warning because dml_log2 returns an unexpected negative value: shift exponent 4294966273 is too large for 32-bit type 'int' [HOW] In the case PTEBufferSizeInRequests is zero, skip the dml_log2() and assign the result directly.Show less
1Linux
1Linux Kernel
Aug 4, 2026
May 2, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix perf_output_begin parameter is incorrectly invoked in perf_event_bpf_output syzkaller reportes a KASAN issue with stack-out-of-bounds....Show more
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix perf_output_begin parameter is incorrectly invoked in perf_event_bpf_output syzkaller reportes a KASAN issue with stack-out-of-bounds. The call trace is as follows: dump_stack+0x9c/0xd3 print_address_description.constprop.0+0x19/0x170 __kasan_report.cold+0x6c/0x84 kasan_report+0x3a/0x50 __perf_event_header__init_id+0x34/0x290 perf_event_header__init_id+0x48/0x60 perf_output_begin+0x4a4/0x560 perf_event_bpf_output+0x161/0x1e0 perf_iterate_sb_cpu+0x29e/0x340 perf_iterate_sb+0x4c/0xc0 perf_event_bpf_event+0x194/0x2c0 __bpf_prog_put.constprop.0+0x55/0xf0 __cls_bpf_delete_prog+0xea/0x120 [cls_bpf] cls_bpf_delete_prog_work+0x1c/0x30 [cls_bpf] process_one_work+0x3c2/0x730 worker_thread+0x93/0x650 kthread+0x1b8/0x210 ret_from_fork+0x1f/0x30 commit 267fb27352b6 ("perf: Reduce stack usage of perf_output_begin()") use on-stack struct perf_sample_data of the caller function. However, perf_event_bpf_output uses incorrect parameter to convert small-sized data (struct perf_bpf_event) into large-sized data (struct perf_sample_data), which causes memory overwriting occurs in __perf_event_header__init_id.Show less