Skip to content
Noroxi

CWE-787 · 10,893 records

Out-of-bounds Write

CVEs in this class

10,000 records

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerJun 23, 2015

  • VMware vCenter Server Out-of-Bounds Write Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    vmware · vcenter serverOct 25, 2023

  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    openslp · openslpDec 6, 2019

  • Serv-U Remote Memory Escape Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 91%

    solarwinds · serv-uJul 14, 2021

  • Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x

    CriticalCVSS 9.8KEVWeaponizedEPSS 89%

    adobe · acrobatDec 7, 2011

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN.

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    tenda · ac11 firmwareMay 7, 2021

  • Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execu

    HighCVSS 8.8KEVWeaponizedEPSS 95%

    microsoft · officeJan 9, 2018

  • WatchGuard Firebox iked Out of Bounds Write Vulnerability

    CriticalCVSS 9.3KEVWeaponizedEPSS 91%

    watchguard · firewareSep 17, 2025

  • A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    fortinet · fortiproxyFeb 9, 2024

  • Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).

    CriticalCVSS 10.0KEVWeaponizedEPSS 80%

    oracle · solarisOct 21, 2020

  • Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a

    CriticalCVSS 9.8KEVWeaponizedEPSS 79%

    adobe · acrobatAug 30, 2013

  • Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t

    HighCVSS 7.8KEVWeaponizedEPSS 98%

    adobe · acrobatNov 4, 2008

  • Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att

    CriticalCVSS 9.8KEVWeaponizedEPSS 74%

    adobe · flash playerApr 14, 2015

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    CriticalCVSS 9.8KEVWeaponizedEPSS 72%

    exim · eximDec 14, 2010

  • Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3,

    HighCVSS 7.8KEVWeaponizedEPSS 97%

    microsoft · officeApr 14, 2015

  • Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitra

    HighCVSS 8.8KEVWeaponizedEPSS 84%

    microsoft · xml core servicesJun 13, 2012

  • The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    adobe · acrobatJan 13, 2010

  • The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem

    HighCVSS 8.8KEVWeaponizedEPSS 83%

    microsoft · edgeNov 10, 2016

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    HighCVSS 7.8KEVWeaponizedEPSS 94%

    polkit project · polkitJan 28, 2022

  • Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execut

    HighCVSS 7.8KEVWeaponizedEPSS 93%

    microsoft · officeJan 9, 2018

  • Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x

    HighCVSS 8.1KEVWeaponizedEPSS 91%

    adobe · flash playerFeb 16, 2012

  • The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remo

    HighCVSS 7.5KEVWeaponizedEPSS 94%

    microsoft · jscriptMay 10, 2016

  • Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office

    HighCVSS 7.8KEVWeaponizedEPSS 89%

    microsoft · officeNov 9, 2010

  • Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c

    HighCVSS 7.8KEVWeaponizedEPSS 87%

    adobe · acrobatFeb 13, 2013

All vulnerability classes