Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEd
The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protec
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privilege escalation due to
OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows
OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows
OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows
OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability all
GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att
hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken f
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buf
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_pu
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integr
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bound
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMac
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMt
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtu
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWa
Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service
Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash t
Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash
Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri
tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started