← Back
CWE-787

14,796 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,796)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1W9 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.
1Tenda
1W9 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.
1Tenda
1W9 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.
1Tenda
1M3 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
1Tenda
1M3 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
1Tenda
1M3 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
1Tenda
1M3 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
1Tenda
1M3 Firmware
Jun 17, 2026
Dec 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
1Opendesign
1Drawings Sdk
Jun 17, 2026
Dec 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverag...Show more
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Clickhouse
2Clickhouse
Clickhouse Cloud
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could sen...Show more
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of Gorilla codec that crashes the ClickHouse server process. This attack does not require authentication. This issue has been addressed in ClickHouse Cloud version 23.9.2.47551 and ClickHouse versions 23.10.5.20, 23.3.18.15, 23.8.8.20, and 23.9.6.20.Show less
1Glensawyer
1Mp3gain
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Dec 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Tats
3Extra Packages For Enterprise Linux
FedoraW3m
Jun 17, 2026
Dec 21, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to th...Show more
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.Show less
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.