CWE-787
14,853 CVEs • Abstraction: Base • Likelihood of Exploit: High
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
CVEs (14,853)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Pa...Show more |
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload |
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload |
A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to den...Show more |
1Cisco 1Adaptive Security Appliance Software Jun 17, 2026 May 3, 2022 N/A· v4 7.1 HIGH· v3 7.0 HIGH· v2 A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cau...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
2Adobe Debian2Debian Linux Xmp Toolkit Software Development KitJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user in...Show more |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions. |
ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Apr 29, 2022 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue. |
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buf...Show more |
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer...Show more |
1Ibm 1Security Verify Password Synchronization Jun 17, 2026 Apr 27, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An auth...Show more |
1Ibm 1Security Verify Password Synchronization Jun 17, 2026 Apr 27, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An auth...Show more |
2Bender Ibm5 Ibm Rational Lifecycle Integration Adapter For Windchill Cc612 FirmwareCc613 Firmware+2 moreJun 17, 2026 Apr 27, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable. |
5Debian FedoraprojectHp+2 more19Caas Platform Cifs UtilsDebian Linux+16 moreJun 17, 2026 Apr 27, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. |
A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). |
2Fedoraproject Giflib Project2Fedora GiflibJun 17, 2026 Apr 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45. |
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PD...Show more |