← Back
CWE-787

14,849 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. P...Show more
In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696073; Issue ID: ALPS07696073.Show less
2Google
Openwrt
2Android
Openwrt
Jun 17, 2026
May 15, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...Show more
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07856356 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07856356 / ALPS07874388 (For MT6880 and MT6890 only).Show less
2Google
Openwrt
2Android
Openwrt
Jun 17, 2026
May 15, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...Show more
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734012 / ALPS07874363 (For MT6880, MT6890, MT6980 and MT6990 only); Issue ID: ALPS07734012 / ALPS07874363 (For MT6880, MT6890, MT6980 and MT6990 only).Show less
2Google
Openwrt
2Android
Openwrt
Jun 17, 2026
May 15, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...Show more
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only).Show less
3Fedoraproject
LibrawRedhat
3Enterprise Linux
FedoraLibraw
Jun 17, 2026
May 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a den...Show more
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a den...Show more
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a de...Show more
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a den...Show more
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, mem...Show more
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, me...Show more
An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Codesys
17Control For Beaglebone Sl
Control For Empc A/imx6 SlControl For Iot2000 Sl+14 more
Jun 17, 2026
May 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwritin...Show more
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.Show less
1Autodesk
13ds Max Usd
Jun 17, 2026
May 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution.
1Google
1Chrome
Jun 17, 2026
May 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High...Show more
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)Show less
1Intel
3Battery Life Diagnostic Tool
Oneapi Base ToolkitSoc Watch
Jun 17, 2026
May 12, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.