Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vuln
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escal
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printe
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This
A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that w
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
In the Linux kernel, the following vulnerability has been resolved: NFS: fix an incorrect limit in filelayout_decode_la
Memory corruption while redirecting log file to any file location with any file name.
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If in
In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT W
Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially craft
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_
In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix wrong list_del in smc_lgr_cleanup_earl
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au
In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial o
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed
In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing boun
In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. T
In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This co
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi
In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After exec
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove
A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-b
A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-b
A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started