← Back
CWE-787

14,870 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,870)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
1Totolink
1Nr1800x Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
1Apache
1Commons Jxpath
Jun 17, 2026
Oct 6, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesti...Show more
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.Show less
1Apache
1Commons Jxpath
Jun 17, 2026
Oct 6, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesti...Show more
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.Show less
1Omron
1Cx Programmer
Jun 17, 2026
Oct 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
1Omron
1Cx Programmer
Jun 17, 2026
Oct 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
1Omron
1Cx Programmer
Jun 17, 2026
Oct 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
1Asus
1Rt Ax56u Firmware
Jun 17, 2026
Oct 6, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the us...Show more
A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability allows an attacker to execute commands remotely. The vulnerability requires authentication.Show less
1Autodesk
1Subassembly Composer
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilitie...Show more
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
11Autocad
Autocad Advance SteelAutocad Architecture+8 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilitie...Show more
A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
11Autocad
Autocad Advance SteelAutocad Architecture+8 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code...Show more
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.Show less
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could...Show more
A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
1Autodesk
4Advanced Material Exchange
Moldflow AdviserMoldflow Communicator+1 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjun...Show more
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Axiosys
1Bento4
Jun 17, 2026
Oct 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
1Axiosys
1Bento4
Jun 17, 2026
Oct 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.