Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 232/286
7.5
CVE-2020-24387

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explic

7.5
CVE-2020-24388

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validat

7.5
CVE-2020-9869

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A

7.5
CVE-2020-27196

An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly par

7.5
CVE-2020-17052

Scripting Engine Memory Corruption Vulnerability

7.5
CVE-2020-17053

Internet Explorer Memory Corruption Vulnerability

7.5
CVE-2020-17058

Microsoft Browser Memory Corruption Vulnerability

7.5
CVE-2020-25464

Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is onl

7.5
CVE-2020-29573

sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer ov

7.5
CVE-2020-13985

An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone

7.5
CVE-2020-17443

An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6

7.5
CVE-2020-8285

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcar

7.5
CVE-2020-29363

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC p

7.5
CVE-2020-7837

An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD

7.5
CVE-2020-35376

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to

7.5
CVE-2019-16747

In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and

7.5
CVE-2019-25001

An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio

7.4
CVE-2020-7065

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, c

7.4
CVE-2020-15208

In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of

7.3
CVE-2020-8450

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer ove

7.3
CVE-2020-4265

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b

7.3
CVE-2020-11904

The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Wri

7.3
CVE-2020-27337

An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe

7.2
CVE-2019-15661

An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida

7.2
CVE-2019-15665

An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida

7.2
CVE-2020-1990

A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to

7.2
CVE-2019-20767

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor

7.2
CVE-2018-21135

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700 befor

7.2
CVE-2018-21163

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200Bv4

7.2
CVE-2018-21174

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor

7.2
CVE-2018-21175

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor

7.2
CVE-2018-21176

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor

7.2
CVE-2018-21177

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor

7.2
CVE-2018-21181

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 befor

7.2
CVE-2020-3309

A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to

7.2
CVE-2020-2006

A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated us

7.2
CVE-2020-2027

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrato

7.2
CVE-2020-3269

Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers

7.2
CVE-2020-3286

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3287

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3288

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3289

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3290

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3291

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3292

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3293

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3294

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3295

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3296

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-19891

DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename an

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started