← Back
CWE-787

14,855 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,855)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Photoshop
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of...Show more
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious U3D file.Show less
1Adobe
1Photoshop
Jun 17, 2026
May 6, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of...Show more
Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Tenda
1Ax1806 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS).
1Tenda
1Ax1806 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS).
1Tenda
1Ax1806 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS).
1Tenda
1Ax1806 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).
1Tenda
1Ax1806 Firmware
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS).
2Debian
Webkitgtk
2Debian Linux
Webkitgtk
Jun 17, 2026
May 6, 2022
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
1Rti
2Connext Professional
Connext Secure
Jun 17, 2026
May 5, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.
2Fedoraproject
Squirrel Lang
2Fedora
Squirrel
Jun 17, 2026
May 4, 2022
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
1Cisco
4Rv340 Firmware
Rv340w FirmwareRv345 Firmware+1 more
Jun 17, 2026
May 4, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due t...Show more
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute remote code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.Show less
1Tenda
1Ac15 Firmware
Jun 17, 2026
May 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are...Show more
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971Show less
1Fujitsu
12Lifebook A3510 Firmware
Lifebook E449 FirmwareLifebook E459 Firmware+9 more
Jun 17, 2026
May 4, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U...Show more
An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The FjGabiFlashCoreAbstractionSmm driver registers a Software System Management Interrupt (SWSMI) handler that is not sufficiently validated to ensure that the CommBuffer (or any other communication buffer's nested contents) are not pointing to SMRAM contents. A potential attacker can therefore write fixed data to SMRAM, which could lead to data corruption inside this memory (e.g., change the SMI handler's code or modify SMRAM map structures to break input pointer validation for other SMI handlers). Thus, the attacker could elevate privileges from ring 0 to ring -2 and execute arbitrary code in SMM.Show less
1Tenda
1Ax12 Firmware
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.
1Secomea
9Sitemanager 1129 Firmware
Sitemanager 1139 FirmwareSitemanager 1149 Firmware+6 more
Jun 17, 2026
May 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.
2Fedoraproject
Libsdl
2Fedora
Sdl Ttf
Jun 17, 2026
May 4, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
2Google
Linux
2Android
Linux Kernel
Jun 17, 2026
May 3, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...Show more
In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330702; Issue ID: DTV03330702.Show less
2Google
Linux
2Android
Linux Kernel
Jun 17, 2026
May 3, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp...Show more
In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.Show less
2Google
Linux
2Android
Linux Kernel
Jun 17, 2026
May 3, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...Show more
In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.Show less
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...Show more
In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296442.Show less