Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 244/286
9.8
CVE-2019-2285

Out of bound write issue is observed while giving information about properties that have been set so far for playing vid

9.8
CVE-2019-2302

While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead

9.8
CVE-2019-2332

Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdrag

9.8
CVE-2019-18655

File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera

9.8
CVE-2019-2205

In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free.

9.8
CVE-2019-18240

In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an

9.8
CVE-2019-8246

Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l

9.8
CVE-2019-8247

Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea

9.8
CVE-2019-8248

Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea

9.8
CVE-2019-11171

Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially en

9.8
CVE-2019-13581

An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa

9.8
CVE-2019-13582

An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa

9.8
CVE-2018-8879

Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.

9.8
CVE-2019-5866

Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potential

9.8
CVE-2019-19307

An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infin

9.8
CVE-2019-12526

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. W

9.8
CVE-2019-14896

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr

9.8
CVE-2019-14895

A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell

9.8
CVE-2019-14897

A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An atta

9.8
CVE-2019-14901

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri

9.8
CVE-2019-18609

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that

9.8
CVE-2019-19333

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi

9.8
CVE-2019-19334

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi

9.8
CVE-2019-5544 KEV

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of

9.8
CVE-2019-18671

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out

9.8
CVE-2019-19635

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl a

9.8
CVE-2019-19638

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c,

9.8
CVE-2019-5085

An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, v

9.8
CVE-2019-5093

An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so

9.8
CVE-2019-10559

Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem

9.8
CVE-2019-2320

Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd

9.8
CVE-2019-18289

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18293

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18295

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18296

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18323

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18324

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18325

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18326

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18327

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18328

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18329

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-18330

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces

9.8
CVE-2019-3951

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of

9.8
CVE-2019-18801

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outs

9.8
CVE-2019-16735

A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk

9.8
CVE-2019-16736

A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and P

9.8
CVE-2019-18257

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist

9.8
CVE-2019-10525

Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB

9.8
CVE-2019-10614

Out of boundary access is possible as there is no validation of data accessed against the received size of the packet in

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started