Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-787 · Out-of-bounds writeDefinition on MITRE ↗Clear

100 results·Page 1 / 2

CVE-2026-11645
2026-06-09
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds writeCWE-125 · Out-of-bounds read
Refschromereleases.googleblog.comissues.chromium.orgnvd.nist.gov
Federal remediation due 2026-06-23
CVE-2026-0300
2026-05-06
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

CWE-787 · Out-of-bounds write
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2026-05-09
CVE-2026-3909
2026-03-13
Google Skia Out-of-Bounds Write Vulnerability
Google

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2026-03-27
CVE-2024-37079
2026-01-23
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.

CWE-787 · Out-of-bounds write
Refssupport.broadcom.comnvd.nist.gov
Federal remediation due 2026-02-13
CVE-2025-14733
2025-12-19
WatchGuard Firebox Out of Bounds Write Vulnerability
WatchGuard

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

CWE-787 · Out-of-bounds write
RefsCheck for signs of potential compromise on all internet accessible instances after applying mitigations. For more information please seenvd.nist.gov
Federal remediation due 2025-12-26
CVE-2025-9242
2025-11-12
WatchGuard Firebox Out-of-Bounds Write Vulnerability
WatchGuard

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

CWE-787 · Out-of-bounds write
Refswatchguard.comnvd.nist.gov
Federal remediation due 2025-12-03
CVE-2025-21042
2025-11-10
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.

CWE-787 · Out-of-bounds write
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2025-12-01
CVE-2021-22555
2025-10-06
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

CWE-787 · Out-of-bounds write
Refsgit.kernel.orggit.kernel.orgsecurity.netapp.comgithub.comnvd.nist.gov
Federal remediation due 2025-10-27
CVE-2025-21043
2025-10-02
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.

CWE-787 · Out-of-bounds write
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2025-10-23
CVE-2025-43300
2025-08-21
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

CWE-787 · Out-of-bounds write
Refssupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2025-09-11
CVE-2025-5419
2025-06-05
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2025-06-26
CVE-2025-27363
2025-05-06
FreeType Out-of-Bounds Write Vulnerability
FreeType

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2025-05-27
CVE-2024-53197
2025-04-09
Linux Kernel Out-of-Bounds Access Vulnerability
Linux

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seesource.android.comnvd.nist.gov
Federal remediation due 2025-04-30
CVE-2025-24201
2025-03-13
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Apple

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refssupport.apple.comsupport.apple.comsupport.apple.comsupport.apple.comnvd.nist.gov
Federal remediation due 2025-04-03
CVE-2024-53104
2025-02-05
Linux Kernel Out-of-Bounds Write Vulnerability
Linux

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2025-02-26
CVE-2024-4761
2024-05-16
Google Chromium V8 Out-of-Bounds Memory Write Vulnerability
Google

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-06-06
CVE-2024-23296
2024-03-06
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-03-27
CVE-2024-23225
2024-03-06
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2024-03-27
CVE-2024-21762
2024-02-09
Fortinet FortiOS Out-of-Bound Write VulnerabilityRansomware
Fortinet

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

CWE-787 · Out-of-bounds write
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2024-02-16
CVE-2023-34048
2024-01-22
VMware vCenter Server Out-of-Bounds Write Vulnerability
VMware

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

CWE-787 · Out-of-bounds write
Refsvmware.comnvd.nist.gov
Federal remediation due 2024-02-12
CVE-2024-0519
2024-01-17
Google Chromium V8 Out-of-Bounds Memory Access Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2024-02-07
CVE-2023-7024
2024-01-02
Google Chromium WebRTC Heap Buffer Overflow Vulnerability
Google

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

CWE-787 · Out-of-bounds write
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-23
CVE-2023-42917
2023-12-04
Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-12-25
CVE-2023-20109
2023-10-10
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Cisco

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.

CWE-787 · Out-of-bounds write
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-31
CVE-2023-5217
2023-10-02
Google Chromium libvpx Heap Buffer Overflow Vulnerability
Google

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2023-10-23
CVE-2023-26369
2023-09-14
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Adobe

Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.

CWE-787 · Out-of-bounds write
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-10-05
CVE-2023-4863
2023-09-13
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Google

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2023-10-04
CVE-2021-25372
2023-06-29
Samsung Mobile Devices Improper Boundary Check Vulnerability
Samsung

Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.

CWE-787 · Out-of-bounds write
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2023-07-20
CVE-2023-32435
2023-06-23
Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-07-14
CVE-2023-28206
2023-04-10
Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability
Apple

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-05-01
CVE-2021-30900
2023-03-30
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple

Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2023-04-20
CVE-2022-4135
2022-11-28
Google Chromium GPU Heap Buffer Overflow Vulnerability
Google

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refschromereleases.googleblog.comnvd.nist.gov
Federal remediation due 2022-12-19
CVE-2022-41128
2022-11-08
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Microsoft

Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.

CWE-787 · Out-of-bounds write
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-12-09
CVE-2022-41125
2022-11-08
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

CWE-787 · Out-of-bounds write
Refsportal.msrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-12-09
CVE-2022-41073
2022-11-08
Microsoft Windows Print Spooler Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

CWE-787 · Out-of-bounds write
Refsportal.msrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-12-09
CVE-2022-42827
2022-10-25
Apple iOS and iPadOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2022-11-15
CVE-2022-37969
2022-09-14
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2022-10-05
CVE-2022-32917
2022-09-14
Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
Apple

Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2022-10-05
CVE-2021-38406
2022-08-25
Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability
Delta Electronics

Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.

CWE-787 · Out-of-bounds write
Refscisa.govnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2022-32894
2022-08-18
Apple iOS and macOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2022-09-08
CVE-2022-32893
2022-08-18
Apple iOS and macOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refssupport.apple.comnvd.nist.gov
Federal remediation due 2022-09-08
CVE-2021-4034
2022-06-27
Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityRansomware
Red Hat

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-9907
2022-06-27
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2020-3837
2022-06-27
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2019-5825
2022-06-08
Google Chromium V8 Out-of-Bounds Write Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-6065
2022-06-08
Google Chromium V8 Integer Overflow Vulnerability
Google

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-190 · Integer overflowCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2018-17480
2022-06-08
Google Chromium V8 Out-of-Bounds Write Vulnerability
Google

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2016-5198
2022-06-08
Google Chromium V8 Out-of-Bounds Memory Vulnerability
Google

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2012-0754
2022-06-08
Adobe Flash Player Memory Corruption Vulnerability
Adobe

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2011-2462
2022-06-08
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Adobe

The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
Prev1 / 2Next