← Back
CWE-787

14,824 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,824)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
4Ipados
Iphone OsMac Os X+1 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing...Show more
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.Show less
1Qualcomm
182Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+179 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industri...Show more
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon WearablesShow less
1Fortinet
1Fortiweb
Jun 17, 2026
Sep 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22.
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the a...Show more
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.Show less
2Debian
Tuxera
2Debian Linux
Ntfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
2Debian
Simplesystems
2Debian Linux
Libtiff
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
3Debian
FedoraprojectTuxera
3Debian Linux
FedoraNtfs 3g
Jul 9, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
4Debian
FedoraprojectRedhat+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vul...Show more
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.Show less
1Espressif
1Esp Idf
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range...Show more
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.Show less
3Fedoraproject
NetappVim
3Fedora
Ontap Select Deploy Administration UtilityVim
Jun 17, 2026
Sep 6, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
vim is vulnerable to Heap-based Buffer Overflow