CWE-787
14,750 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,750)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied...Show more |
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to mani...Show more |
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption. |
1Qualcomm 49Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+46 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
1Qualcomm 49Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+46 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
1Qualcomm 25Fastconnect 6700 Firmware Fastconnect 6900 FirmwareQca6595au Firmware+22 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer. |
1Qualcomm 65C V2x 9150 Firmware Fastconnect 6200 FirmwareFastconnect 6800 Firmware+62 moreJun 17, 2026 Apr 7, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Memory corruption while accessing MSM channel map and mixer functions. |
2Google Mediatek19Android Mt2718Mt6781+16 moreJun 17, 2026 Apr 7, 2025 N/A· v4 6.0 MEDIUM· v3 N/A· v2 In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User...Show more |
In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not ne...Show more |
5Google LinuxfoundationMediatek+2 more20Android Mt6781Mt6789+17 moreJun 17, 2026 Apr 7, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges ne...Show more |
2Mediatek Openwrt8Mt6890 Mt7622Mt7915+5 moreJun 17, 2026 Apr 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for explo...Show more |
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability. |
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability. |
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument s...Show more |
1Qinguoyi 1Tinywebserver Jun 17, 2026 Apr 4, 2025 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argumen...Show more |
A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName...Show more |
A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation of the argument Password le...Show more |