CWE-787

High likelihood

Out-of-bounds Write

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product writes data past the end, or before the beginning, of the intended buffer.

14,407 vulnerabilities with CWE-787
CVE-2026-31521 MEDIUM
module: Fix kernel panic when a symbol st_shndx is out of bounds
CVSS 5.5
CVE-2026-31505 HIGH
iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()
CVSS 7.8
CVE-2026-31494 HIGH
net: macb: use the current queue number for stats
CVSS 7.8
CVE-2026-31470 HIGH
virt: tdx-guest: Fix handling of host controlled 'quote' buffer length
CVSS 7.1
CVE-2026-31452 HIGH
ext4: convert inline data to extents when truncate exceeds inline size
CVSS 7.8
CVE-2026-31432 HIGH
ksmbd: fix OOB write in QUERY_INFO for compound requests
CVSS 8.8
CVE-2026-41144 NONE
F´ (F Prime) has Integer Overflow in FileUplink
CVE-2026-3298 HIGH
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
CVE-2026-6784 HIGH
Memory safety bugs fixed in Firefox 150 and Thunderbird 150
CVSS 7.5
CVE-2026-6753 HIGH
Incorrect boundary conditions in the WebRTC component
CVSS 7.3
CVE-2026-5450 CRITICAL
glibc 2.7-2.43 - Heap-based Buffer Overflow via scanf %mc with Explicit Width
CVSS 9.8
CVE-2026-40494 CRITICAL
SAIL has heap buffer overflow in TGA RLE decoder — raw packet path missing bounds check
CVSS 9.8
CVE-2026-40493 CRITICAL
SAIL has heap buffer overflow in PSD decoder — bpp mismatch in LAB 16-bit mode
CVSS 9.8
CVE-2026-40492 CRITICAL
SAIL has heap buffer overflow in XWD decoder — bits_per_pixel vs pixmap_depth type confusion in byte-swap
CVSS 9.8
CVE-2026-40489 HIGH
editorconfig-core-c has incomplete fix for CVE-2023-0341
CVE-2026-27890 HIGH
Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments
CVSS 8.2
CVE-2026-6507 HIGH
Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing
CVSS 7.5
CVE-2026-6314 HIGH
Google Chrome < 147.0.7727.101 - Out-of-bounds Write in GPU
CVSS 8.3
CVE-2026-6305 HIGH
Google Chrome < 147.0.7727.101 - Remote Code Execution via PDFium Heap Buffer Overflow
CVSS 8.8
CVE-2026-40919 MEDIUM
Gimp: gimp: denial of service via specially crafted seattle filmworks file
CVSS 6.1
CVE-2026-40916 MEDIUM
Gimp: gimp: denial of service due to stack buffer overflow in tim image loader
CVSS 5.0
CVE-2026-40688 HIGH
FortiWeb 8.0.0-8.0.3, 7.6.0-7.6.6, 7.4.0-7.4.11 - Authenticated Remote Code Execution via Crafted HTTP Requests
CVSS 7.2
CVE-2026-27295 HIGH
Adobe Framemaker | Out-of-bounds Write (CWE-787)
CVSS 7.8
CVE-2026-34631 HIGH
InCopy | Out-of-bounds Write (CWE-787)
CVSS 7.8
CVE-2026-34618 HIGH
Illustrator | Out-of-bounds Write (CWE-787)
CVSS 7.8
Details
Vulnerabilities 14,407
Exploit Likelihood High