CWE-787
14,870 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,870)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. |
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the...Show more |
1Qualcomm 16Sd429 Firmware Sd 8 Gen1 5g FirmwareSda429w Firmware+13 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, Snapdragon Wearables |
1Qualcomm 16Sd429 Firmware Sd 8 Gen1 5g FirmwareSda429w Firmware+13 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon Mobile, Snapdragon Wearables |
In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges nee...Show more |
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User intera...Show more |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string. |
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. |
hutool-json v5.8.10 was discovered to contain an out of memory error. |
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. |
2Debian Jettison Project2Debian Linux JettisonJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data. |
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set . |
ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow. |
A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please no...Show more |
An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Pleas...Show more |
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full comprom...Show more |
1Cisco 13Ip Phone 7811 Firmware Ip Phone 7821 FirmwareIp Phone 7832 Firmware+10 moreJun 17, 2026 Dec 12, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. Thi...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open(...Show more |
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo. |
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave. |