← Back
CWE-787

14,792 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,792)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/af_afade.c in crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.
2Debian
Ffmpeg
2Debian Linux
Ffmpeg
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequ...Show more
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.Show less
3Datakit
LuxionSiemens
4Crosscadware
KeyshotSolid Edge Se2020 Firmware+1 more
Jun 17, 2026
May 27, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing CATPart files. This co...Show more
Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing CATPart files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.Show less
3Fedoraproject
LinuxNetapp
12Cloud Backup
FedoraH300e Firmware+9 more
Jun 17, 2026
May 27, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, l...Show more
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction change, which then results in an incorrect final aux->alu_limit.Show less
1Huawei
5Ngfw Module Firmware
Secospace Usg6300 FirmwareSecospace Usg6500 Firmware+2 more
Jun 17, 2026
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the ba...Show more
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the module.Affected product versions include: NGFW Module versions V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;Secospace USG6500 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;USG9500 versions V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200.Show less
1Huawei
4Cloudengine 12800 Firmware
Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 more
Jun 17, 2026
May 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sending crafted data in the packet to the target device. Due to insufficient validation of message, suc...Show more
There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sending crafted data in the packet to the target device. Due to insufficient validation of message, successful exploit can cause certain service abnormal.Affected product versions include:CloudEngine 12800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800;CloudEngine 5800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800@;CloudEngine 6800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800,V200R019C10SPC800;CloudEngine 7800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800.Show less
1Trendmicro
1Home Network Security
Jun 17, 2026
May 27, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code...Show more
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.Show less
2Fedoraproject
Libcaca Project
2Fedora
Libcaca
Jun 17, 2026
May 27, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
3Debian
FedoraprojectFig2dev Project
3Debian Linux
FedoraFig2dev
Jun 17, 2026
May 26, 2021
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause...Show more
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.Show less
2Fedoraproject
Libcaca Project
2Fedora
Libcaca
Jun 17, 2026
May 26, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.