← Back
CWE-787

14,870 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,870)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Axiosys
1Bento4
Jun 17, 2026
Oct 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
1Nasm
1Netwide Assembler
Jun 17, 2026
Oct 3, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
1Sonicjs
1Sonicjs
Jun 17, 2026
Oct 1, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any f...Show more
SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.Show less
1Cisco
1Wireless Lan Controller Software
Jun 17, 2026
Sep 30, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected dev...Show more
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to cause the wireless LAN controller to crash, resulting in a DoS condition. Note: This vulnerability affects only devices that have Federal Information Processing Standards (FIPS) mode enabled.Show less
1Xpdfreader
1Xpdf
Jun 17, 2026
Sep 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
1Xpdfreader
1Xpdf
Jun 17, 2026
Sep 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
1Flipperzero
1Flipper Zero Firmware
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.
2Debian
Ruby Lang
2Debian Linux
Ruby
Nov 21, 2024
Sep 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Special...Show more
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.Show less
1Wolfssl
1Wolfssl
Jun 17, 2026
Sep 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry...Show more
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.Show less
1Dell
1Smartfabric Os10
Jun 17, 2026
Sep 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans.
2Debian
Graphicsmagick
2Debian Linux
Graphicsmagick
Jun 17, 2026
Sep 28, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
1Tenda
1Tx3 Firmware
Jun 17, 2026
Sep 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.
1Sony
2Playstation 4 Firmware
Playstation 5 Firmware
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap...Show more
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.Show less
3Debian
FedoraprojectVim
3Debian Linux
FedoraVim
Jun 17, 2026
Sep 27, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
1Toaruos
1Toaruos
Jun 17, 2026
Sep 27, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.
1Westerndigital
3My Cloud Home Duo Firmware
My Cloud Home FirmwareSandisk Ibi Firmware
Jun 17, 2026
Sep 27, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version f...Show more
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.Show less
1Mipcm
1Mipc Camera Firmware
Jun 17, 2026
Sep 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Sep 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Sep 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Google
3Chrome
FedoraLinux And Chrome Os
Jun 17, 2026
Sep 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corrupt...Show more
Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.Show less