← Back
CWE-787

14,809 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,809)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Htslib
1Htslib
Jun 17, 2026
Jul 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
1Soliditylang
1Solidity
Jun 17, 2026
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but does not have a code change.
1Zeromq
1Libzmq
Jun 17, 2026
Jul 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.
1Rarlab
1Unrar
Nov 21, 2024
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
1Rawspeed
1Rawspeed
Nov 21, 2024
Jul 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.
1Rarlab
1Unrar
Nov 21, 2024
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds memory write.
3Debian
Djvulibre ProjectFedoraproject
3Debian Linux
DjvulibreFedora
Jun 17, 2026
Jun 30, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to...Show more
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.Show less
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure dur...Show more
Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.Show less
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and...Show more
Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and information disclosure.Show less
1Nvidia
1Jetson Linux
Jun 17, 2026
Jun 30, 2021
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.
2Apache
Debian
2Debian Linux
Traffic Server
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
1Poweriso
1Poweriso
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially crafted DMG file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger...Show more
A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially crafted DMG file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. The vendor fixed it in a bug-release of the current version.Show less
1Fatek
1Winproladder
Jun 17, 2026
Jun 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
1Opentext
1Brava! Desktop
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target mus...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13679.Show less
1Opentext
1Brava! Desktop
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target mus...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of BMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13678.Show less
1Opentext
1Brava! Desktop
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target mus...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13676.Show less