Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 129/286
5.9
CVE-2023-3024

Forcing the Bluetooth LE stack to segment 'prepare write response' packets can lead to an out-of-bounds memory access.

5.9
CVE-2023-5568

A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit th

5.9
CVE-2023-42538

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to

5.9
CVE-2023-48230

Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ H

5.8
CVE-2023-3894

Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the par

5.7
CVE-2023-26470

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t

5.7
CVE-2023-28401

Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255

5.6
CVE-2023-26551

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be a

5.6
CVE-2023-26552

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be

5.6
CVE-2023-26553

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary ma

5.6
CVE-2023-26554

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be

5.6
CVE-2023-28393

A stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft Ima

5.6
CVE-2023-42557

Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute a

5.5
CVE-2022-39116

In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local

5.5
CVE-2022-39118

In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local

5.5
CVE-2022-44427

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44428

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44429

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44430

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44431

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47086

GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_m

5.5
CVE-2021-46791

Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted

5.5
CVE-2023-24056

In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgcon

5.5
CVE-2022-48281

processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of siz

5.5
CVE-2022-20235

The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written

5.5
CVE-2022-31902

Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

5.5
CVE-2021-36535

Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js f

5.5
CVE-2021-37519

Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted au

5.5
CVE-2022-38675

In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o

5.5
CVE-2022-42783

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44448

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47364

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o

5.5
CVE-2022-47365

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o

5.5
CVE-2022-47366

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o

5.5
CVE-2022-47368

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47369

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47452

In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o

5.5
CVE-2023-20949

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This

5.5
CVE-2022-45586

Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a deni

5.5
CVE-2022-45587

Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial o

5.5
CVE-2022-47457

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47459

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2023-27754

vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The fl

5.5
CVE-2023-27249

swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

5.5
CVE-2023-20952

In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This

5.5
CVE-2022-47337

In media service, there is a missing permission check. This could lead to local denial of service in media service.

5.5
CVE-2023-1906

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/q

5.5
CVE-2023-29579

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note:

5.5
CVE-2023-29582

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note

5.5
CVE-2023-29583

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started