CWE-787
High likelihoodOut-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
14,406 vulnerabilities with CWE-787
CVE-2026-10643
HIGH
Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
CVSS 8.7
CVE-2026-45258
HIGH
FreeBSD sound(4) mmap - Integer Overflow Privilege Escalation
CVSS 7.8
CVE-2026-46604
HIGH
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
CVSS 7.5
CVE-2026-57876
HIGH
GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)
CVSS 7.5
CVE-2026-6325
HIGH
Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
CVSS 7.5
CVE-2026-6681
MEDIUM
PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
CVSS 5.3
CVE-2026-6679
HIGH
DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
CVSS 7.5
CVE-2026-55958
HIGH
Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
CVSS 7.5
CVE-2026-56786
CRITICAL
RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
CVSS 9.8
CVE-2026-49839
HIGH
jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
CVSS 7.1
CVE-2026-57455
HIGH
Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument
CVSS 7.8
CVE-2026-55892
MEDIUM
Vim: Out-of-bounds Write in Spell File Prefix Dump
CVSS 5.5
CVE-2026-55693
HIGH
Vim: Out-of-bounds Write in Spell File Word Count
CVSS 7.8
CVE-2026-12844
HIGH
List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function
CVSS 7.5
CVE-2026-47151
HIGH
Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
CVSS 7.1
CVE-2026-47150
HIGH
IAS Zone enroll invalid table index and write in EmberZNet 9.0.2
CVSS 7.1
CVE-2026-53246
CRITICAL
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVSS 9.8
CVE-2026-53209
HIGH
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVSS 7.8
CVE-2026-53205
HIGH
accel/ivpu: Add bounds checks for firmware log indices
CVSS 7.1
CVE-2026-53203
HIGH
accel/ivpu: Add buffer overflow check in MS get_info_ioctl
CVSS 7.1
CVE-2026-53196
MEDIUM
USB: serial: io_ti: fix heap overflow in get_manuf_info()
CVSS 6.8
CVE-2026-53195
HIGH
Linux Kernel io_ti USB Serial - Heap Overflow
CVSS 7.8
CVE-2026-53194
HIGH
USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVSS 7.8
CVE-2026-53187
HIGH
RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
CVSS 7.1
CVE-2026-53173
HIGH
accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
CVSS 7.8
Details
Vulnerabilities
14,406
Exploit Likelihood
High