← Back
CWE-787

14,870 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,870)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1W6 S Firmware
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.
1Tenda
1A18 Firmware
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
2Openatom
Openharmony
2Openharmony
Openharmony
Jun 17, 2026
Dec 8, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorre...Show more
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.Show less
1Avas!t
1Script Shield
Jun 17, 2026
Dec 8, 2022
N/A· v4
10.0 CRITICAL· v3
N/A· v2
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applic...Show more
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component. Show less
1Ge
1Cimplicity
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.
1Trendnet
1Tew 820ap Firmware
Jun 17, 2026
Dec 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution.
1Omron
1Cx Programmer
Jun 17, 2026
Dec 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
1Omron
1Cx Programmer
Jun 17, 2026
Dec 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
1Google
1Tensorflow
Jun 17, 2026
Dec 6, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes...Show more
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is triggered. We have patched the issue in GitHub commit a65411a1d69edfb16b25907ffb8f73556ce36bb7. The fix will be included in TensorFlow 2.11.0. We will also cherrypick this commit on TensorFlow 2.8.4, 2.9.3, and 2.10.1.Show less
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
1Gpac
1Gpac
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.
1Force1rc
1Discovery Wifi U818a Hd+ Fpv Firmware
Jun 17, 2026
Dec 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the R...Show more
Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/ > https://www.bostoncyber.org/ > https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368Show less
4Apple
HaxxNetapp+1 more
8Clustered Data Ontap
CurlH300s Firmware+5 more
Jun 17, 2026
Dec 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the...Show more
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.Show less
1Sangoma
1Asterisk
Jul 2, 2026
Dec 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
1Google
1Android
Jun 17, 2026
Dec 5, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...Show more
In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138646; Issue ID: ALPS07138646.Show less