← Back
CWE-787

14,853 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,853)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ripple
1Rippled
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This expo...Show more
A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.Show less
1Lenovo
1Pcmanager
Jun 17, 2026
Apr 22, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an attacker with local access to trigger a blue screen error.
1Radare
1Radare2
Jun 17, 2026
Apr 22, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive informati...Show more
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.Show less
2Fedoraproject
Freetype
2Fedora
Freetype
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
3Debian
FedoraprojectGnome
3Debian Linux
EpiphanyFedora
Jun 17, 2026
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for...Show more
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.Show less
1Autodesk
1Navisworks
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFTron earlier than 9.0.7 version in Autodesk Navisworks 2022, and 2020.
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
10Advance Steel
AutocadAutocad Architecture+7 more
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arb...Show more
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.Show less
1Autodesk
10Advance Steel
AutocadAutocad Architecture+7 more
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited t...Show more
A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.Show less
1Autodesk
1Design Review
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in...Show more
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
1Design Review
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabiliti...Show more
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
2Fedoraproject
Opensc Project
2Fedora
Opensc
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
3Fedoraproject
Opensc ProjectRedhat
3Enterprise Linux
FedoraOpensc
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
1Pixar
1Openusd
Jun 17, 2026
Apr 18, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the...Show more
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability could be used to bypass mitigations and aid additional exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided file.Show less
1Radare
1Radare2
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive informati...Show more
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.Show less
3Apple
FedoraprojectVim
3Fedora
MacosVim
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
1Wasm3 Project
1Wasm3
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in m3_compile.c).
17 Zip
17 Zip
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow....Show more
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occurShow less
1Microsoft
17Windows 10 1507
Windows 10 1607Windows 10 1809+14 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
2Fisglobal
Yottadb
2Gt.m
Yottadb
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or cras...Show more
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application.Show less