Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 18/286
7.8
CVE-2026-48409

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t

7.8
CVE-2026-48410

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t

7.8
CVE-2026-54758

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEd

7.8
CVE-2026-58087

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protec

7.8
CVE-2026-16873

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privilege escalation due to

7.8
CVE-2026-18288

OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows

7.8
CVE-2026-18289

OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows

7.8
CVE-2026-18290

OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows

7.8
CVE-2026-18293

OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability all

7.8
CVE-2026-18295

GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att

7.8
CVE-2026-72852

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken f

7.8
CVE-2026-16946

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buf

7.8
CVE-2026-16783

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A

7.8
CVE-2026-7455

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A

7.8
CVE-2026-16233

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-64204

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-48418

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48419

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48420

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48421

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48426

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48427

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-71382

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-71564

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-75749

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-75770

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.7
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can

7.7
CVE-2026-30929

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

7.7
CVE-2026-36355

The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo

7.7
CVE-2026-46123

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_pu

7.7
CVE-2026-17003

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integr

7.6
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)

7.6
CVE-2026-5068

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD

7.6
CVE-2026-7831

UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v

7.6
CVE-2026-19387

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D

7.6
CVE-2026-18693

An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges

7.6
CVE-2026-16907

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bound

7.5
CVE-2025-13151

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin

7.5
CVE-2025-70753

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function

7.5
CVE-2025-71024

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMac

7.5
CVE-2025-71025

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMt

7.5
CVE-2025-71026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtu

7.5
CVE-2025-71027

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWa

7.5
CVE-2021-47786

Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service

7.5
CVE-2021-47789

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash t

7.5
CVE-2026-24827

Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs

7.5
CVE-2026-22260

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash

7.5
CVE-2020-37011

Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri

7.5
CVE-2026-25061

tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame

7.5
CVE-2025-62601

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started