← Back
CWE-787

14,862 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,862)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chafa Project
1Chafa
Jun 17, 2026
Jun 13, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.
1Apache
1Hadoop
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade...Show more
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.Show less
2Debian
Oracle
2Debian Linux
Linux
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect t...Show more
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).Show less
2Debian
Teluu
2Debian Linux
Pjsip
Jun 17, 2026
Jun 9, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack b...Show more
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use STUN in their applications, either by: setting a STUN server in their account/media config in PJSUA/PJSUA2 level, or directly using `pjlib-util/stun_simple` API. A patch is available in commit 450baca which should be included in the next release. There are no known workarounds for this issue.Show less
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraMacos+1 more
Jun 17, 2026
Jun 9, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
1Mi
1Miui
Jun 17, 2026
Jun 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddMacList parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetAPWifiorLedInfoById parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTimingtimeWifiAndLed parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditWlanMacList parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetMobileAPInfoById parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnet parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddWlanMacList parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnetDebug parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateSnat parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateMacClone parameter at /goform/aspForm.
1H3c
1Magic R100 Firmware
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at /goform/aspForm.