Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking d
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow
An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 l
Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X
Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reacha
: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet p
In builds with PubSub and JSON enabled, a crafted JSON message can cause the decoder to write beyond a heap-allocated ar
Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec
Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially result
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space
Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is assoc
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat
F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ri
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c
Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the applicatio
Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported pl
Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms
Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platfor
SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a
LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars
LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b
Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable
Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[]
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (Mi
Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionali
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started