VYPR

CWE-787

Out-of-bounds Write

BaseDraftLikelihood: High

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Hierarchy (View 1000)

CVEs mapped to this weakness (14,608)

page 577 of 731
  • CVE-2018-8372HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.25

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from…

  • CVE-2018-8266HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.27

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,…

  • CVE-2018-3632MedJul 10, 2018
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be triggered by an attacker with local administrator permission on the system.

  • CVE-2018-12693MedJun 23, 2018
    risk 0.44cvss 6.5epss 0.16

    Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.

  • CVE-2018-10120HigApr 16, 2018
    risk 0.44cvss 7.8epss 0.02

    The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or…

  • CVE-2026-19696MedAug 13, 2026
    risk 0.43cvss 6.6epss 0.00

    Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

  • CVE-2026-46123HigMay 28, 2026
    risk 0.43cvss 7.7epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_put virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device.…

  • CVE-2026-24640MedMar 10, 2026
    risk 0.43cvss 6.6epss 0.01

    A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can…

  • CVE-2026-30929HigMar 10, 2026
    risk 0.43cvss 7.7epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This…

  • CVE-2026-1788MedFeb 3, 2026
    risk 0.43cvss epss 0.00

    : Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3.

  • CVE-2025-48839MedNov 18, 2025
    risk 0.43cvss 6.6epss 0.00

    An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

  • CVE-2025-4544MedMay 11, 2025
    risk 0.43cvss 6.6epss 0.11

    A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_max/def_tcp_time/def_udp_max/def_udp_time/d…

  • CVE-2025-20964MedMay 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20963MedMay 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2024-45581MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while sound model registration for voice activation with audio kernel driver.

  • CVE-2024-45563MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

  • CVE-2024-45543MedApr 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while accessing MSM channel map and mixer functions.

  • CVE-2024-38413MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing frame packets.

  • CVE-2025-20642MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2025-20641MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…