← Back
CWE-787

14,833 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,833)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jerryscript
1Jerryscript
Jun 17, 2026
Jan 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.
1Jerryscript
1Jerryscript
Jun 17, 2026
Jan 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.
1Jerryscript
1Jerryscript
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.
1Moddable
1Moddable Sdk
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.
1Moddable
1Moddable Sdk
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.
1Moddable
1Moddable Sdk
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.
1Moddable
1Moddable Sdk
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.
1Espruino
1Espruino
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.
1Espruino
1Espruino
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
5Advanced Intrusion Detection Environment Project
CanonicalDebian+2 more
7Advanced Intrusion Detection Environment
Debian LinuxEnterprise Linux+4 more
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
1Libspf2 Project
1Libspf2
Jun 17, 2026
Jan 19, 2022
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, beca...Show more
libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount of overflowed data depends on the relationship between the length of an entire domain name and the length of its leftmost label. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.Show less
2Debian
Libspf2 Project
2Debian Linux
Libspf2
Jun 17, 2026
Jan 19, 2022
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS re...Show more
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.Show less
1Nvidia
1Shield Experience
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which m...Show more
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.Show less
1Mi
1Xiaomi Mirror Screen
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.
3Apple
DebianVim
4Debian Linux
Mac Os XMacos+1 more
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
1Allwinnertech
1Android Q Sdk
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.
1Opendesign
1Drawings Software Development Kit
Jun 17, 2026
Jan 15, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code...Show more
Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.Show less
1Spinroot
1Spin
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.
1Omron
1Cx One
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...Show more
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less