Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the
An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker
D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some pr
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.r
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Up
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Updat
An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-ba
RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Z
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. Thi
Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or
Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race conditio
An issue was discovered in the rusb crate before 0.7.0 for Rust. Because of a lack of Send and Sync bounds, a data race
An issue was discovered in the aovec crate through 2020-12-10 for Rust. Because Aovec<T> does not have bounds on its Sen
An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send
The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allo
The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe
Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based B
Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metad
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to c
Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before
NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user.
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could le
In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to loca
OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data
Scripting Engine Memory Corruption Vulnerability
NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 befor
Scripting Engine Memory Corruption Vulnerability
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6400v2 bef
In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of pri
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In netdiag, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalatio
In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of pri
In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of
In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
Heap overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.4
In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o
In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local e
In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line in
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a hea
In Write of NxpMfcReader.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to
In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started