← Back
CWE-787

14,849 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dlink
1Dir 619 Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.
1Dlink
1Dir 619 Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
1Dlink
1Dir 619 Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
1Dlink
1Dir 619 Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
1Dlink
1Dir 619 Ax Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
1Dlink
1Dir 619 Ax Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
1Mruby
1Mruby
Jun 17, 2026
Apr 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
1Gpac
1Gpac
Jun 17, 2026
Apr 8, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.
1Gpac
1Gpac
Jun 17, 2026
Apr 8, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.
1Zlog Project
1Zlog
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.
2Libsixel
Libsixel Project
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
1Asus
1Rt Ac86u Firmware
Jun 17, 2026
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary...Show more
ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.Show less
1Asus
1Rt Ax56u Firmware
Jun 17, 2026
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform...Show more
ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.Show less
1Tenda
1Ac9 Firmware
Jun 17, 2026
Apr 7, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.
1Tenda
1Ac9 Firmware
Jun 17, 2026
Apr 7, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.
2Debian
Pjsip
2Debian Linux
Pjsip
Jun 17, 2026
Apr 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that dire...Show more
PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.Show less
1Struktur
1Libde265
Jun 17, 2026
Apr 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
1Radare
1Radare2
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` functi...Show more
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).Show less
1Radare
1Radare2
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see...Show more
Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).Show less