Cwe 787

🧬 CWE Related 105
slug: cwe-787

Explanation

CWE-787はCWE-119の中でも特に「メモリの確保された範囲外に書き込んでしまう」欠陥です。 書き込みできるとプログラムを完全に乗っ取れる (任意コード実行) ことが多く、CVSSスコアが極めて高くなりがちです。 MITREの「危険な脆弱性Top 25」で常に上位を占めています。
📌 Example
CVE-2024-30088 (Windows Kernel): Windowsカーネルの境界外書き込みで、攻撃者がローカル権限昇格を達成できた。CISA KEV入り。

🔖 Related tags

🛡 Vulnerabilities tagged with this 1,733

ID Title
CVE-2022-33047 OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
CVE-2022-32385 Out-of-Bounds Write in tendacn (CVE-2022-32385)
CVE-2022-32386 Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
CVE-2022-32384 Out-of-Bounds Write in tendacn (CVE-2022-32384)
CVE-2022-34835 Out-of-Bounds Write in denx (CVE-2022-34835)
CVE-2021-4034 KEV [KEV] Out-of-Bounds Write in Red hat red-hat (CVE-2021-4034)
CVE-2020-3837 KEV [KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2020-3837)
CVE-2020-9907 KEV [KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2020-9907)
CVE-2022-30790 Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
CVE-2019-5825 KEV [KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2019-5825)
CVE-2018-6065 KEV [KEV] Vulnerability in Google chromium-v8 (CVE-2018-6065)
CVE-2018-17480 KEV [KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2018-17480)
CVE-2016-5198 KEV [KEV] Out-of-Bounds Read in Google chromium-v8 (CVE-2016-5198)
CVE-2012-0754 KEV [KEV] Out-of-Bounds Write in Adobe flash-player (CVE-2012-0754)
CVE-2011-2462 KEV [KEV] Out-of-Bounds Write in Adobe reader-and-acrobat (CVE-2011-2462)
CVE-2010-1297 KEV [KEV] Out-of-Bounds Write in Adobe flash-player (CVE-2010-1297)
CVE-2021-22791 Out-of-Bounds Write in dos (CVE-2021-22791)
CVE-2021-39537 Out-of-Bounds Write in c (CVE-2021-39537)
CVE-2021-33289 Out-of-Bounds Write in tuxera (CVE-2021-33289)
CVE-2021-35269 Out-of-Bounds Write in tuxera (CVE-2021-35269)
CVE-2021-35267 Out-of-Bounds Write in tuxera (CVE-2021-35267)
CVE-2021-35266 Out-of-Bounds Write in c (CVE-2021-35266)
CVE-2021-38166 Vulnerability in c (CVE-2021-38166)
CVE-2021-33485 CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
CVE-2020-21831 Out-of-Bounds Write in c (CVE-2020-21831)
CVE-2020-21842 Out-of-Bounds Write in c (CVE-2020-21842)
CVE-2020-21838 Out-of-Bounds Write in c (CVE-2020-21838)
CVE-2020-21832 Out-of-Bounds Write in c (CVE-2020-21832)
CVE-2020-21830 Out-of-Bounds Write in c (CVE-2020-21830)
CVE-2020-21836 Out-of-Bounds Write in c (CVE-2020-21836)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →