An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explic
An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validat
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly par
Scripting Engine Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
Microsoft Browser Memory Corruption Vulnerability
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is onl
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer ov
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone
An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcar
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and
An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, c
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer ove
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b
The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Wri
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida
A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200Bv4
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 befor
A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to
A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated us
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrato
Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started