CWE-787
14,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses a guest-controlled SS:SP-derived offset a...Show more |
Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c. The handler computes a destination offs...Show more |
1Qualcomm 42Cologne Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+39 moreJul 22, 2026 Jun 1, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing multiple IOCTL command for escape operations. |
1Qualcomm 21Cologne Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+18 moreJul 22, 2026 Jun 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory Corruption when sending random number generator command with insufficient output buffer size. |
1Qualcomm 50Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+47 moreJul 22, 2026 Jun 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption in diagnostic services due to absence of input validation |
1Qualcomm 134Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+131 moreJul 22, 2026 Jun 1, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when processing device identifier strings that exceed the expected maximum length. |
1Mediatek 6Mt7902 Firmware Mt7920 FirmwareMt7921 Firmware+3 moreJul 22, 2026 Jun 1, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch...Show more |
1Mediatek 36Mt6739 Firmware Mt6761 FirmwareMt6765 Firmware+33 moreJul 22, 2026 Jun 1, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is no...Show more |
1Mediatek 36Mt6739 Firmware Mt6761 FirmwareMt6765 Firmware+33 moreJul 22, 2026 Jun 1, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is no...Show more |
A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This manipulation causes out-...Show more |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitma...Show more |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_Ca...Show more |
Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium...Show more |
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security s...Show more |
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) |
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security...Show more |
Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |