Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attac
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple v
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products i
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component o
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o
An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able
Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially expl
Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exp
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via par
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs s
When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not co
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruptio
Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption
Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that w
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCre
TP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safar
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execu
Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compac
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidenc
Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that w
A stack-based buffer overflow vulnerability exists in the libzebra.so.0.0.0 security_decrypt_password functionality of M
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of th
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially e
Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to
In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type fun
Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromise
Heap buffer overflow in Visuals in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploi
Out of bounds read and write in WebGL in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, C
libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could l
In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This cou
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started