A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a la
libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos7570, 7580, 7870, 7880, and 889
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solu
An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLo
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a b
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers caus
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an intege
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly valida
An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for
In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. Thi
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), w
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG),
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a lo
An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A special
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if
In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remo
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been
A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) o
<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle
An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorC
An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that c
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started