← Back
CWE-787

14,869 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,869)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asustor
1Adm
Jun 17, 2026
Aug 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include:...Show more
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below.Show less
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.
6Apple
DebianFedoraproject+3 more
18Active Iq Unified Manager
Debian LinuxFedora+15 more
Jul 14, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applicati...Show more
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).Show less
1Uniwill
1Sparkio.sys
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
1Triplecross Project
1Triplecross
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no limit to the length of program parameters.
1Luadec Project
1Luadec
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
1Santesoft
1Dicom Viewer Pro
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.9.2. User interaction is required to exploit this vulnerability in that the target must visit a...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.9.2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16679.Show less
2Debian
Intel
2Connman
Debian Linux
Jun 17, 2026
Aug 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
1Milkytracker Project
1Milkytracker
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.
1Hinet
1Hicos Natural Person Credential Component Client
Jun 17, 2026
Aug 2, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitra...Show more
HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.Show less
1Nhi
1Health Insurance Web Service Component
Jun 17, 2026
Aug 2, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerabil...Show more
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.Show less
1Nhi
1Health Insurance Web Service Component
Jun 17, 2026
Aug 2, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerabi...Show more
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.Show less
1Nhi
1Health Insurance Web Service Component
Jun 17, 2026
Aug 2, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit...Show more
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.Show less
2Debian
Vim
2Debian Linux
Vim
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420088; Issue ID: GN20220420088.Show less
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420075; Issue ID: GN20220420075.Show less
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420068; Issue ID: GN20220420068.Show less
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420051; Issue ID: GN20220420051.Show less
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420044; Issue ID: GN20220420044.Show less
1Mediatek
13Mt7603 Firmware
Mt7610 FirmwareMt7612 Firmware+10 more
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220420037; Issue ID: GN20220420037.Show less