A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort o
A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/
A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the
A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::
The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allow
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supply
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key inpu
Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local att
Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the applicatio
SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the appli
Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the applica
RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application
WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to c
R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows l
Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the applic
NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the
NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash
VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the applicatio
Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputti
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local
Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers t
Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by sup
Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows
TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the
Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that al
RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allow
RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local
ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local at
DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field tha
NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attacke
HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the applic
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows
WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that al
MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplyin
AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by suppl
MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application
FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by su
NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup feature that allows local attackers to crash t
NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that
NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to c
FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by in
Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local att
ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of
LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started