River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash t
SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows at
TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supp
BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers t
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the app
Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to
UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image
Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplyi
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secur
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi
Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (unco
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalat
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization.
darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect av
Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting
A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthentica
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability
NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v
Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersiz
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started