Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 147/286
8.1
CVE-2021-41987

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that l

8.1
CVE-2021-26112

Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpret

8.1
CVE-2022-26098

Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 a

8.1
CVE-2022-27568

Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 all

8.1
CVE-2022-27569

Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 all

8.1
CVE-2022-27570

Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Releas

8.1
CVE-2022-27571

Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Rel

8.1
CVE-2022-27572

Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 all

8.1
CVE-2022-23677

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 1

8.1
CVE-2022-28998

Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive inf

8.1
CVE-2022-38742

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An at

8.1
CVE-2022-41674

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer ov

8.1
CVE-2021-37789

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service

8.1
CVE-2022-0324

There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that

8.1
CVE-2022-20968

A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could

8.1
CVE-2022-41981

A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-c

8.1
CVE-2022-43598

Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project

8.0
CVE-2022-39852

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release

8.0
CVE-2022-39882

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allo

8.0
CVE-2022-26513

Out-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauth

7.8
CVE-2021-45926

MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called fr

7.8
CVE-2021-45927

MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd6e029ee0) in mdb_numeric_to_string (called fr

7.8
CVE-2021-22045

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and

7.8
CVE-2021-43579

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co

7.8
CVE-2021-36412

A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video functio

7.8
CVE-2021-36414

A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a

7.8
CVE-2022-21917

HEVC Video Extensions Remote Code Execution Vulnerability

7.8
CVE-2021-36417

A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, whic

7.8
CVE-2021-45053

Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitra

7.8
CVE-2021-45056

Adobe InCopy version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitra

7.8
CVE-2021-45057

Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbit

7.8
CVE-2021-45058

Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbit

7.8
CVE-2021-34871

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34873

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34875

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34876

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34877

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34878

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34892

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34893

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34896

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34897

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34898

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34899

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34900

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34903

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34904

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34905

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34907

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

7.8
CVE-2021-34914

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started