← Back
CWE-787

14,870 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,870)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1Tx3 Firmware
Jun 17, 2026
Oct 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.
1Tenda
1Tx3 Firmware
Jun 17, 2026
Oct 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.
1Tenda
1Tx3 Firmware
Jun 17, 2026
Oct 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.
1Tenda
1Tx3 Firmware
Jun 17, 2026
Oct 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
1Jsonlint Project
1Jsonlint C++
Jun 17, 2026
Oct 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.
1Fujielectric
1D300win
Jun 17, 2026
Oct 19, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an attacker to overwrite program memory to manipulate the flow of information.
1Gpac
1Gpac
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.
1Gpac
1Gpac
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isomedia/meta.c.
1Gpac
1Gpac
Jun 17, 2026
Oct 19, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isom_intern.c.
1Gpac
1Gpac
Jun 17, 2026
Oct 19, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.
1Gpac
1Gpac
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at /isomedia/meta.c.
1Axiosys
1Bento4
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.
1Axiosys
1Bento4
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
1Axiosys
1Bento4
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.
1Acer
1Altos W2000h W570h F4 Firmware
Jul 9, 2026
Oct 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into...Show more
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.Show less
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraGit+1 more
Jun 17, 2026
Oct 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32...Show more
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into an array improperly uses an `int` to represent the number of entries in the array, allowing a malicious actor to intentionally overflow the return value, leading to arbitrary heap writes. Because the resulting array is then passed to `execv()`, it is possible to leverage this attack to gain remote code execution on a victim machine. Note that a victim must first allow access to `git shell` as a login shell in order to be vulnerable to this attack. This problem is patched in versions 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 and users are advised to upgrade to the latest version. Disabling `git shell` access via remote logins is a viable short-term workaround.Show less
1Tenda
1Ac18 Firmware
Jun 17, 2026
Oct 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
1Tenda
1Ac15 Firmware
Jun 17, 2026
Oct 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
1Tenda
1Ac10 Firmware
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.
1Tenda
1Ac10 Firmware
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.