iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulner
A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V
In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-boun
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mo
Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled con
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ve
In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds ch
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK param
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPa
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key param
D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially c
An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write b
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data
A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft Image
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validati
Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could poten
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-00
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchO
TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d
Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. Th
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and he
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not vali
Win32k Elevation of Privilege Vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.4. An
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a spec
A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple ca
TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determ
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a l
Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check.
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular
When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started