Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bh
A missing null-termination character in the last element of an nvlist array string can lead to writing outside the alloc
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens
Out-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation o
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacen
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent n
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent netw
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when pa
In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard max
Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote a
In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote den
In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote deni
Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even m
Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or ev
Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service
A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enti
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This functio
A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bo
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and pri
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The v
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Pr
In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode
In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid data corruption caused by decline W
A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of Automa
A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of Automa
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through
Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted requ
An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controll
Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, ob
Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that w
In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_stat
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started