CWE-787

High likelihood

Out-of-bounds Write

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product writes data past the end, or before the beginning, of the intended buffer.

14,407 vulnerabilities with CWE-787
CVE-2026-31697 HIGH
crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed
CVSS 7.1
CVE-2026-31696 HIGH
rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
CVSS 7.8
CVE-2026-5405 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-5403 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-40685 MEDIUM
Exim < 4.99.2 - Heap-Based Buffer Overflow via Malformed JSON Header Processing
CVSS 6.5
CVE-2026-31786 HIGH
Buffer overflow in drivers/xen/sys-hypervisor.c
CVSS 7.8
CVE-2026-7426 HIGH
Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCP
CVSS 8.1
CVE-2026-41220 HIGH
Acronis DeviceLock DLP < 9.0.93212 & Cyber Protect Cloud Agent < 42183 - Local Privilege Escalation
CVSS 7.8
CVE-2026-7354 HIGH
Google Chrome < 147.0.7727.138 - Out-of-bounds Read and Write in Angle
CVSS 8.8
CVE-2026-7323 HIGH
Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1
CVSS 7.3
CVE-2026-7322 HIGH
Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1
CVSS 7.3
CVE-2026-5435 HIGH
Potential buffer overflow in ns_sprintrrf TSIG handling path
CVSS 7.3
CVE-2026-31690 HIGH
firmware: thead: Fix buffer overflow and use standard endian macros
CVSS 7.8
CVE-2026-6786 HIGH
Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 7.5
CVE-2026-6785 HIGH
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 7.5
CVE-2026-41907 HIGH
uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
CVSS 7.5
CVE-2026-41678 HIGH
rust-openssl: Incorrect bounds assertion in aes key wrap
CVSS 8.1
CVE-2026-41676 HIGH
rust-openssl 0.9.27-0.10.77 - Memory Corruption
CVSS 7.5
CVE-2026-31631 HIGH
rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()
CVSS 8.2
CVE-2026-31607 CRITICAL
usbip: validate number_of_packets in usbip_pack_ret_submit()
CVSS 9.8
CVE-2026-33317 HIGH
OP-TEE 3.13.0-4.10.0 - Out-of-bounds Read in PKCS#11 TA Heap via Bad Template Parameter
CVSS 8.7
CVE-2026-41990 MEDIUM
Libgcrypt <1.12.2 - Memory Corruption
CVSS 4.0
CVE-2026-41989 MEDIUM
Libgcrypt < 1.12.2 - Heap-Based Buffer Overflow via Crafted ECDH Ciphertext
CVSS 6.7
CVE-2026-26354 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6, 8.3.1.0-8.3.1.10, 7.13.1.0-7.13.1.60 - Stack-based Buffer Overflow
CVSS 8.1
CVE-2026-31525 HIGH
bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
CVSS 7.8
Details
Vulnerabilities 14,407
Exploit Likelihood High