Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-787

MITRE ↗

Out-of-bounds Write

2,513
CRITICAL
8,761
HIGH
2,814
MEDIUM
124
LOW
14,298 CVEs · Page 65/286
8.8
CVE-2024-56626

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_

8.6
CVE-2023-43520

Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mappi

8.6
CVE-2024-20259

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to

8.6
CVE-2024-20308

A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthent

8.6
CVE-2024-34199

TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sendi

8.6
CVE-2024-36114

Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr

8.6
CVE-2024-5696

By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentiall

8.6
CVE-2024-2011

A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denia

8.6
CVE-2023-7272

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to caus

8.6
CVE-2024-20375

A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unifi

8.6
CVE-2024-34657

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary

8.6
CVE-2024-20433

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software coul

8.6
CVE-2024-20499

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate

8.6
CVE-2024-20501

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate

8.6
CVE-2024-52063

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L

8.5
CVE-2024-39825

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation o

8.4
CVE-2023-33033

Memory corruption in Audio during playback with speaker protection.

8.4
CVE-2023-33113

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

8.4
CVE-2023-6246

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called

8.4
CVE-2024-20812

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arb

8.4
CVE-2024-20813

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arb

8.4
CVE-2023-43517

Memory corruption in Automotive Multimedia due to improper access control in HAB.

8.4
CVE-2024-20029

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local esc

8.4
CVE-2023-33066

Memory corruption in Audio while processing RT proxy port register driver.

8.4
CVE-2023-43540

Memory corruption while processing the IOCTL FM HCI WRITE request.

8.4
CVE-2023-43549

Memory corruption while processing TPC target power table in FTM TPC.

8.4
CVE-2024-22005

there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privileg

8.4
CVE-2024-25993

In tmu_reset_tmu_trip_counter of , there is a possible out of bounds write due to a missing bounds check. This could lea

8.4
CVE-2024-27204

In tmu_set_gov_active of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead t

8.4
CVE-2024-27208

there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege

8.4
CVE-2024-27219

In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local

8.4
CVE-2024-27226

In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to

8.4
CVE-2024-20053

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of

8.4
CVE-2023-28547

Memory corruption in SPS Application while requesting for public key in sorter TA.

8.4
CVE-2024-20844

Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allo

8.4
CVE-2024-20845

Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local at

8.4
CVE-2024-29746

In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead t

8.4
CVE-2024-29749

In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lea

8.4
CVE-2024-21474

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

8.4
CVE-2021-47352

In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This ad

8.4
CVE-2023-52829

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound write in at

8.4
CVE-2024-31956

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length

8.4
CVE-2024-32504

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos

8.4
CVE-2024-37676

An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSett

8.4
CVE-2023-43554

Memory corruption while processing IOCTL handler in FastRPC.

8.4
CVE-2024-21481

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

8.4
CVE-2024-38218

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

8.4
CVE-2024-38386

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

8.4
CVE-2024-39816

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o

8.4
CVE-2024-33045

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Frequently Asked Questions

What is CWE-787?

CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-787?

There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.

How can I protect against CWE-787 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.

Detect CWE-787 Vulnerabilities

CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.

Get Started