← Back
CWE-787

14,829 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,829)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1Ac10v4 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi.
1Tenda
1Ac8 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.
1Juplink
1Rx4 1500 Firmware
Jun 17, 2026
Aug 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code execution as root.
2Artifex
Redhat
9Codeready Linux Builder
Codeready Linux Builder For Arm64Codeready Linux Builder For Ibm Z Systems+6 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat E...Show more
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.Show less
1Silabs
1Gecko Bootloader
Jun 17, 2026
Aug 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser mod...Show more
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This issue affects "Standalone" and "Application" versions of Gecko Bootloader.Show less
1Hitachi
1Eh View
Jun 17, 2026
Aug 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is req...Show more
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Show less
1Hitachi
1Eh View
Jun 17, 2026
Aug 23, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required...Show more
** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a malicious file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Supermicro
271H11dsi Nt Firmware
H11dsi FirmwareH11dst B Firmware+268 more
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
1Cryptopp
1Crypto++
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. N...Show more
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.Show less
1Perl
1Perl
Jun 17, 2026
Aug 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
2Busybox
Debian
2Busybox
Debian Linux
Jul 14, 2026
Aug 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.