← Back
CWE-787

14,831 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,831)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libxls Project
1Libxls
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the get_string function in xlstool.c:395.
1Libxls Project
1Libxls
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the transcode_latin1_to_utf8 function in xlstool.c:296.
1Libxls Project
1Libxls
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1015.
1Libxls Project
1Libxls
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the unicode_decode_wcstombs function in xlstool.c:266.
1Libxls Project
1Libxls
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1018.
1Google
1Android
Jun 17, 2026
Aug 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is...Show more
In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Show less
1Google
1Android
Jun 17, 2026
Aug 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. Use...Show more
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Show less
1Tenda
1A18 Firmware
Jun 17, 2026
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
1Tenda
1A18 Firmware
Jun 17, 2026
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
1Tenda
1A18 Firmware
Jun 17, 2026
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
1Onlyoffice
1Document Server
Jul 9, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
1Gnu
1Indent
Jun 17, 2026
Aug 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
1Eminfedar
1Async Sockets Cpp
Jun 17, 2026
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.
10branch
1Boron
Jun 17, 2026
Aug 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.
10branch
1Boron
Jun 17, 2026
Aug 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_parseBlockI at i_parse_blk.c.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Aug 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
2Debian
Eprosima
2Debian Linux
Fast Dds
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID...Show more
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a different program counter. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.Show less
2Debian
Eprosima
2Debian Linux
Fast Dds
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_L...Show more
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a CDR string with length larger than the size of actual content. In `eprosima::fastdds::dds::ParameterPropertyList_t::push_back_helper`, `memcpy` is called to first copy the octet'ized length and then to copy the data into `properties_.data`. At the second memcpy, both `data` and `size` can be controlled by anyone that sends the CDR string to the discovery multicast port. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6 contain a patch for this issue.Show less
1Intel
1Realsense 450 Fa Firmware
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.