VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2021-1445High· 8.6
5y ago

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.7%via NVD
CVE-2021-27365High· 7.8PoC
5y ago

An issue was discovered in the Linux kernel through 5.11.3

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is a…

▾ Midnightnetapp · cloud_backupEPSS 2.1%via NVD
CVE-2021-1732High· 7.8CISA KEV0dayPoC
5y ago

Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1803EPSS 78%via NVD
CVE-2020-24175High· 7.8
5y ago

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.

▾ Twilightyz1 · yz1EPSS 1.8%via NVD
CVE-2020-26664High· 7.8
5y ago

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

▾ Twilightvideolan · vlc_media_playerEPSS 1.5%via NVD
CVE-2019-15992High· 7.2
6y ago

A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitr…

A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitr…

▾ Twilightcisco · adaptive_security_applianceEPSS 4.1%via NVD
CVE-2020-14498Critical· 9.6
6y ago

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

▾ Midnighthms-networks · ecatcherEPSS 4.0%via NVD
CVE-2020-1150High· 7.8
6y ago

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new acc…

▾ Twilightmicrosoft · windows_7EPSS 3.2%via NVD
CVE-2020-1136High· 7.8
6y ago

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new acc…

▾ Twilightmicrosoft · windows_10EPSS 3.8%via NVD
CVE-2020-1126High· 8.8
6y ago

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new acc…

▾ Twilightmicrosoft · windows_10EPSS 4.0%via NVD
CVE-2020-1093High· 7.5
6y ago

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current …

▾ Twilightmicrosoft · internet_explorerEPSS 3.1%via NVD
CVE-2020-1092High· 7.5
6y ago

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u…

▾ Twilightmicrosoft · internet_explorerEPSS 3.1%via NVD
CVE-2020-1065Medium· 4.2
6y ago

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of …

▾ Sunlitmicrosoft · chakracoreEPSS 2.2%via NVD
CVE-2020-1062High· 7.5
6y ago

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u…

▾ Twilightmicrosoft · internet_explorerEPSS 6.2%via NVD
CVE-2020-1061High· 7.5
6y ago

A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory

A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the…

▾ Twilightmicrosoft · windows_10EPSS 3.3%via NVD
CVE-2020-1060High· 7.5
6y ago

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current …

▾ Twilightmicrosoft · internet_explorerEPSS 3.1%via NVD
CVE-2020-1058High· 7.5
6y ago

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current …

▾ Twilightmicrosoft · internet_explorerEPSS 3.1%via NVD
CVE-2020-1054High· 7.0CISA KEVPoC
6y ago

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. …

▾ Abyssalmicrosoft · windows_10_1507EPSS 54%via NVD
CVE-2020-1037Medium· 4.2
6y ago

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitr…

▾ Sunlitmicrosoft · edgeEPSS 2.2%via NVD
CVE-2020-1035High· 7.5
6y ago

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current …

▾ Twilightmicrosoft · internet_explorerEPSS 3.1%via NVD
CVE-2020-1028High· 7.8
6y ago

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new acc…

▾ Twilightmicrosoft · windows_10EPSS 3.8%via NVD
CVE-2020-3283High· 8.6
6y ago

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote att…

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote att…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.0%via NVD
CVE-2020-6851High· 7.5
6y ago

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

▾ Twilightuclouvain · openjpegEPSS 5.2%via NVD
CVE-2018-8174High· 7.5CISA KEV0dayPoC
8y ago

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…

▾ Abyssalmicrosoft · windows_10_1607EPSS 88%via NVD
CVE-2018-0231High· 8.6
8y ago

A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of th…

A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of th…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 4.5%via NVD
CVE-2017-16879High· 7.8
8y ago

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demons…

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demons…

▾ Twilightinvisible-island · ncursesEPSS 2.4%via NVD
CVE-2025-31200High· 7.5CISA KEV0dayPoC

Memory corruption in CoreAudio via crafted media file

A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.

▾ AbyssalApple · CoreAudioiOS, iPadOS, macOSEPSS 19%via NVD
CWE-787 vulnerabilities (CVEs) — page 27 · VulnSea