In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary pe
There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficien
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerabilit
A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOf
A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function g
Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of thi
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle fu
An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds acc
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when ass
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decod
A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the functio
BT: Unchecked user input in bap_broadcast_assistant
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is e
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unkno
There is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit thi
Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect
In drm service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o
In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigg
Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable esca
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of pri
In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserv
Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC s
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attacker
Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attack
Server information leak for the CDA Server process memory can occur when an error is generated in response to a speciall
Server communication with a controller can lead to remote code execution using a specially crafted message from the cont
A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiat
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attac
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So
vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starti
Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege a
Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated mal
Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows l
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect
Frequently Asked Questions
What is CWE-787?
CWE-787 (Out-of-bounds Write) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-787?
There are 17,111 CVE records associated with CWE-787 in our database. Of these, 2513 are critical severity, 8761 are high severity, and 2814 are medium severity.
How can I protect against CWE-787 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-787 using AI-powered security agents.
Detect CWE-787 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds write vulnerabilities across your infrastructure.
Get Started