CWE-787 · 10 893 записей
Out-of-bounds Write
CVE этого класса
10 000 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2023-34048Готовый эксплойт | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Критическая9,8 | KEV | 99,4 % | 25 окт. 2023 г. |
98Срочно | CVE-2019-5544Готовый эксплойт | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Критическая9,8 | KEV | 97,3 % | 6 дек. 2019 г. |
97Срочно | CVE-2021-35211Готовый эксплойт | Serv-U Remote Memory Escape Vulnerabilitysolarwinds · serv-u · CWE-787 | Критическая10,0 | KEV | 91,2 % | 14 июл. 2021 г. |
96Срочно | CVE-2011-2462Готовый эксплойт | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Критическая9,8 | KEV | 88,5 % | 7 дек. 2011 г. |
95Срочно | CVE-2023-4863Готовый эксплойт | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Высокая8,8 | KEV | 100,0 % | 12 сент. 2023 г. |
95Срочно | CVE-2021-31755Готовый эксплойт | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN.tenda · ac11 firmware · CWE-787 | Критическая9,8 | KEV | 86,9 % | 7 мая 2021 г. |
94Срочно | CVE-2018-0798Готовый эксплойт | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execumicrosoft · office · CWE-787 | Высокая8,8 | KEV | 95,1 % | 9 янв. 2018 г. |
94Срочно | CVE-2025-9242Готовый эксплойт | WatchGuard Firebox iked Out of Bounds Write Vulnerabilitywatchguard · fireware · CWE-787 | Критическая9,3 | KEV | 91,3 % | 17 сент. 2025 г. |
94Срочно | CVE-2024-21762Готовый эксплойт | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2fortinet · fortiproxy · CWE-787 | Критическая9,8 | KEV | 83,4 % | 9 февр. 2024 г. |
94Срочно | CVE-2020-14871Готовый эксплойт | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).oracle · solaris · CWE-787 | Критическая10,0 | KEV | 80,2 % | 21 окт. 2020 г. |
93Срочно | CVE-2013-3346Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a adobe · acrobat · CWE-787 | Критическая9,8 | KEV | 78,9 % | 30 авг. 2013 г. |
91Срочно | CVE-2008-2992Готовый эксплойт | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file tadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 98,5 % | 4 нояб. 2008 г. |
91Срочно | CVE-2015-3043Готовый эксплойт | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Критическая9,8 | KEV | 73,9 % | 14 апр. 2015 г. |
91Срочно | CVE-2010-4344Готовый эксплойт | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Критическая9,8 | KEV | 71,7 % | 14 дек. 2010 г. |
90Срочно | CVE-2015-1641Готовый эксплойт | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, microsoft · office · CWE-787 | Высокая7,8 | KEV | 96,7 % | 14 апр. 2015 г. |
90Срочно | CVE-2012-1889Готовый эксплойт | Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitramicrosoft · xml core services · CWE-787 | Высокая8,8 | KEV | 83,5 % | 13 июн. 2012 г. |
90Срочно | CVE-2009-3953Готовый эксплойт | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | Высокая8,8 | KEV | 83,2 % | 13 янв. 2010 г. |
90Срочно | CVE-2016-7200Готовый эксплойт | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memmicrosoft · edge · CWE-787 | Высокая8,8 | KEV | 82,8 % | 10 нояб. 2016 г. |
89Срочно | CVE-2021-4034Готовый эксплойт | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | Высокая7,8 | KEV | 94,3 % | 28 янв. 2022 г. |
89Срочно | CVE-2018-0802Готовый эксплойт | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executmicrosoft · office · CWE-787 | Высокая7,8 | KEV | 93,3 % | 9 янв. 2018 г. |
89Срочно | CVE-2012-0754Готовый эксплойт | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | Высокая8,1 | KEV | 91,2 % | 16 февр. 2012 г. |
88Срочно | CVE-2016-0189Готовый эксплойт | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remomicrosoft · jscript · CWE-787 | Высокая7,5 | KEV | 94,1 % | 10 мая 2016 г. |
88Срочно | CVE-2010-3333Готовый эксплойт | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office microsoft · office · CWE-787 | Высокая7,8 | KEV | 89,5 % | 9 нояб. 2010 г. |
87Срочно | CVE-2013-0640Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | Высокая7,8 | KEV | 86,9 % | 13 февр. 2013 г. |
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2023-3404899Срочно
VMware vCenter Server Out-of-Bounds Write Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %vmware · vcenter server25 окт. 2023 г.
- CVE-2019-554498Срочно
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %openslp · openslp6 дек. 2019 г.
- CVE-2021-3521197Срочно
Serv-U Remote Memory Escape Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 91 %solarwinds · serv-u14 июл. 2021 г.
- CVE-2011-246296Срочно
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %adobe · acrobat7 дек. 2011 г.
- CVE-2023-486395Срочно
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %google · chrome12 сент. 2023 г.
- CVE-2021-3175595Срочно
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %tenda · ac11 firmware7 мая 2021 г.
- CVE-2018-079894Срочно
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execu
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 95 %microsoft · office9 янв. 2018 г.
- CVE-2025-924294Срочно
WatchGuard Firebox iked Out of Bounds Write Vulnerability
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 91 %watchguard · fireware17 сент. 2025 г.
- CVE-2024-2176294Срочно
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %fortinet · fortiproxy9 февр. 2024 г.
- CVE-2020-1487194Срочно
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 80 %oracle · solaris21 окт. 2020 г.
- CVE-2013-334693Срочно
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 79 %adobe · acrobat30 авг. 2013 г.
- CVE-2008-299291Срочно
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 98 %adobe · acrobat4 нояб. 2008 г.
- CVE-2015-304391Срочно
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %adobe · flash player14 апр. 2015 г.
- CVE-2010-434491Срочно
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %exim · exim14 дек. 2010 г.
- CVE-2015-164190Срочно
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3,
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 97 %microsoft · office14 апр. 2015 г.
- CVE-2012-188990Срочно
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitra
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 84 %microsoft · xml core services13 июн. 2012 г.
- CVE-2009-395390Срочно
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %adobe · acrobat13 янв. 2010 г.
- CVE-2016-720090Срочно
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %microsoft · edge10 нояб. 2016 г.
- CVE-2021-403489Срочно
A local privilege escalation vulnerability was found on polkit's pkexec utility.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 94 %polkit project · polkit28 янв. 2022 г.
- CVE-2018-080289Срочно
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execut
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %microsoft · office9 янв. 2018 г.
- CVE-2012-075489Срочно
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 91 %adobe · flash player16 февр. 2012 г.
- CVE-2016-018988Срочно
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remo
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 94 %microsoft · jscript10 мая 2016 г.
- CVE-2010-333388Срочно
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 89 %microsoft · office9 нояб. 2010 г.
- CVE-2013-064087Срочно
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 87 %adobe · acrobat13 февр. 2013 г.