Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a pri
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual chann
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link wi
A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unp
In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free
In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to
In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privileg
In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of pri
In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esc
In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local es
In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privil
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalati
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Sec
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5, Secu
Out of bounds write in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable
Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to poten
HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to i
A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an
In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to
In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check
libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker att
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potential
Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially e
A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to ca
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attack
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially expl
ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to
LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomNam
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets wit
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor a
In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could le
Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote a
In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition. This could le
In the netlink driver, there is a possible out of bounds write due to a race condition. This could lead to local escalat
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local
A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code e
A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow co
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the rend
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a mallo
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started