An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,
Memory corruption in Automotive Android OS due to improper input validation.
Memory corruption in Core due to stack-based buffer overflow.
Memory corruption in core due to stack-based buffer overflow
Memory corruption due to stack-based buffer overflow in Core
NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buf
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may cor
Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticate
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
Memory corruption in Automotive GPU while querying a gsl memory node.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Memory Corruption in HLOS while registering for key provisioning notify.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary cod
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause ou
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause
IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds
Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, informatio
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be
Memory corruption in Automotive due to improper input validation.
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cm
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and inc
In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, b
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in th
Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Releas
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prio
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prio
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from m
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signat
Memory corruption in TZ Secure OS while loading an app ELF.
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and
A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A mal
A stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight
An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bi
Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally mov
An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under ce
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started