← Back to feed Search feed

CWE-787 Out-of-bounds Write vulnerabilities

64 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-31705ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignmentCRITICAL9.832%ileMicrosoft2026-05-12
CVE-2026-17675Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rCRITICAL9.624%ileNVD2026-07-30
CVE-2026-17691Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentiallyCRITICAL9.630%ileNVD2026-07-30
CVE-2026-17721Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a CRITICAL9.624%ileNVD2026-07-30
CVE-2026-17727Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentiallyCRITICAL9.624%ileNVD2026-07-30
CVE-2026-47876VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with CRITICAL9.320%ileNVD2026-07-30
CVE-2026-58154Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affeCRITICAL9.230%ileNVD2026-07-29
CVE-2026-18022Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, wHIGH8.827%ileNVD2026-07-29
CVE-2026-65423An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to tHIGH8.746%ileNVD2026-07-30
CVE-2026-68579FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_HIGH8.719%ileNVD2026-08-02
CVE-2026-58188Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects ApachHIGH8.445%ileNVD2026-07-29
CVE-2026-12927CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code executHIGH8.410%ileNVD2026-07-29
CVE-2026-58177The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This isHIGH8.343%ileNVD2026-07-29
CVE-2026-58184The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition HIGH8.337%ileNVD2026-07-29
CVE-2026-10849The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update serHIGH8.218%ileNVD2026-08-03
CVE-2026-17544Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versionsHIGH8.135%ileNVD2026-07-30
CVE-2026-48392Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%ileNVD2026-07-28
CVE-2026-48393Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%ileNVD2026-07-28
CVE-2026-48394Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%ileNVD2026-07-28
CVE-2026-18220An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. THIGH7.88%ileNVD2026-07-29
CVE-2026-34641Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the coHIGH7.84%ileNVD2026-07-31
CVE-2025-38685fbdev: Fix vmalloc out-of-bounds write in fast_imageblitHIGH7.86%ileMicrosoft2025-09-09
CVE-2026-55693Vim: Out-of-bounds Write in Spell File Word CountHIGH7.82%ileMicrosoft2026-06-09
CVE-2026-57455Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argumentHIGH7.82%ileMicrosoft2026-06-09
CVE-2025-38183net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get()HIGH7.86%ileMicrosoft2025-07-08
CVE-2023-0054Out-of-bounds Write in vim/vimHIGH7.838%ileMicrosoft2023-01-10
CVE-2026-15057IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrHIGH7.518%ileNVD2026-07-28
CVE-2026-6507Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processingHIGH7.539%ileMicrosoft2026-04-14
CVE-2026-37457An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FHIGH7.532%ileMicrosoft2026-05-12
CVE-2026-35226An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same nHIGH7.17%ileNVD2026-07-29
CVE-2026-54715GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the bHIGH7.118%ileNVD2026-07-30
CVE-2026-31505iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()HIGH7.13%ileMicrosoft2026-04-14
CVE-2026-11771OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in theHIGH7.027%ileNVD2026-07-30
CVE-2026-10848The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_jHIGH7.010%ileNVD2026-08-02
CVE-2025-7519Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds writeMEDIUM6.78%ileMicrosoft2025-07-08
CVE-2026-20464In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatioMEDIUM6.528%ileNVD2026-08-03
CVE-2022-25147Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functionsMEDIUM6.570%ileMicrosoft2023-01-10
CVE-2026-58187The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of servMEDIUM6.337%ileNVD2026-07-29
CVE-2026-20466In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalatMEDIUM6.16%ileNVD2026-08-03
CVE-2026-20468In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of MEDIUM6.02%ileNVD2026-08-03
CVE-2026-20475In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oMEDIUM6.02%ileNVD2026-08-03
CVE-2026-20477In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oMEDIUM6.02%ileNVD2026-08-03
CVE-2026-20481In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalationMEDIUM6.01%ileNVD2026-08-03
CVE-2026-20485In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pMEDIUM6.01%ileNVD2026-08-03
CVE-2026-20497In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalationMEDIUM6.01%ileNVD2026-08-03
CVE-2026-20476In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servicMEDIUM5.52%ileNVD2026-08-03
CVE-2026-20478In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of MEDIUM5.51%ileNVD2026-08-03
CVE-2026-20491In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of serMEDIUM5.51%ileNVD2026-08-03
CVE-2026-6695A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (MEDIUM5.55%ileNVD2026-08-03
CVE-2026-55892Vim: Out-of-bounds Write in Spell File Prefix DumpMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2025-7546GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds writeMEDIUM5.37%ileMicrosoft2025-07-08
CVE-2026-62363ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.MEDIUM5.03%ileNVD2026-07-30
CVE-2026-20471In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of serviceMEDIUM4.66%ileNVD2026-08-03
CVE-2026-20472In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servicMEDIUM4.41%ileNVD2026-08-03
CVE-2026-20493In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of serviMEDIUM4.41%ileNVD2026-08-03
CVE-2026-18739A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, whenLOW2.51%ileNVD2026-08-04
CVE-2026-45784rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersUNKNOWN3%ileMicrosoft2026-07-14
CVE-2026-5503out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicNameUNKNOWN32%ileMicrosoft2026-04-14
CVE-2026-5187Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSLUNKNOWN21%ileMicrosoft2026-04-14
CVE-2026-3298Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytesUNKNOWN30%ileMicrosoft2026-04-14
CVE-2026-42250Off-by-One Leading to Out-of-Bounds Write in bzip2UNKNOWN3%ileMicrosoft2026-05-12
CVE-2022-28331Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv functionUNKNOWN73%ileMicrosoft2023-01-10
FG-IR-26-123Out-of-bounds access in CAPWAP daemonUNKNOWNFortinet2026-05-12
FG-IR-26-127Out-Of-Bounds Write in administrative interfaceUNKNOWNFortinet2026-04-15