CWE-787

High likelihood

Out-of-bounds Write

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product writes data past the end, or before the beginning, of the intended buffer.

14,406 vulnerabilities with CWE-787
CVE-2026-10643 HIGH
Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
CVSS 8.7
CVE-2026-45258 HIGH
FreeBSD sound(4) mmap - Integer Overflow Privilege Escalation
CVSS 7.8
CVE-2026-46604 HIGH
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
CVSS 7.5
CVE-2026-57876 HIGH
GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)
CVSS 7.5
CVE-2026-6325 HIGH
Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
CVSS 7.5
CVE-2026-6681 MEDIUM
PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
CVSS 5.3
CVE-2026-6679 HIGH
DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
CVSS 7.5
CVE-2026-55958 HIGH
Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
CVSS 7.5
CVE-2026-56786 CRITICAL
RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
CVSS 9.8
CVE-2026-49839 HIGH
jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow
CVSS 7.1
CVE-2026-57455 HIGH
Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument
CVSS 7.8
CVE-2026-55892 MEDIUM
Vim: Out-of-bounds Write in Spell File Prefix Dump
CVSS 5.5
CVE-2026-55693 HIGH
Vim: Out-of-bounds Write in Spell File Word Count
CVSS 7.8
CVE-2026-12844 HIGH
List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function
CVSS 7.5
CVE-2026-47151 HIGH
Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
CVSS 7.1
CVE-2026-47150 HIGH
IAS Zone enroll invalid table index and write in EmberZNet 9.0.2
CVSS 7.1
CVE-2026-53246 CRITICAL
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVSS 9.8
CVE-2026-53209 HIGH
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVSS 7.8
CVE-2026-53205 HIGH
accel/ivpu: Add bounds checks for firmware log indices
CVSS 7.1
CVE-2026-53203 HIGH
accel/ivpu: Add buffer overflow check in MS get_info_ioctl
CVSS 7.1
CVE-2026-53196 MEDIUM
USB: serial: io_ti: fix heap overflow in get_manuf_info()
CVSS 6.8
CVE-2026-53195 HIGH
Linux Kernel io_ti USB Serial - Heap Overflow
CVSS 7.8
CVE-2026-53194 HIGH
USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVSS 7.8
CVE-2026-53187 HIGH
RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
CVSS 7.1
CVE-2026-53173 HIGH
accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
CVSS 7.8
Details
Vulnerabilities 14,406
Exploit Likelihood High