Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-787 · Out-of-bounds writeDefinition on MITRE ↗Clear

100 results·Page 2 / 2

CVE-2010-1297
2022-06-08
Adobe Flash Player Memory Corruption Vulnerability
Adobe

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2021-30883
2022-05-23
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2020-1027
2022-05-23
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2019-7287
2022-05-23
Apple iOS Memory Corruption Vulnerability
Apple

Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2019-7286
2022-05-23
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2018-5002
2022-05-23
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe

Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2022-24521
2022-04-13
Microsoft Windows CLFS Driver Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds writeCWE-1285
Refsnvd.nist.gov
Federal remediation due 2022-05-04
CVE-2021-39793
2022-04-11
Google Pixel Out-of-Bounds Write Vulnerability
Google

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2018-8373
2022-03-25
Microsoft Scripting Engine Memory Corruption Vulnerability
Microsoft / Internet Explorer Scripting Engine

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2019-16928
2022-03-03
Exim Out-of-bounds Write Vulnerability
Exim / Exim Internet Mailer

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-03-17
CVE-2015-3043
2022-03-03
Adobe Flash Player Memory Corruption Vulnerability
Adobe

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2013-0640
2022-03-03
Adobe Reader and Acrobat Memory Corruption Vulnerability
Adobe

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-03-24
CVE-2018-8174
2022-02-15
Microsoft Windows VBScript Engine Out-of-Bounds Write VulnerabilityRansomware
Microsoft

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-08-15
CVE-2022-21882
2022-02-04
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-02-18
CVE-2022-22587
2022-01-28
Apple Memory Corruption Vulnerability
Apple / iOS and macOS

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.

CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-02-11
CVE-2018-13383
2022-01-10
Fortinet FortiOS and FortiProxy Out-of-bounds WriteRansomware
Fortinet

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2021-35211
2021-11-03
SolarWinds Serv-U Remote Code Execution VulnerabilityRansomware
SolarWinds

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-34448
2021-11-03
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-33742
2021-11-03
Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability
Microsoft

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.

CWE-787 · Out-of-bounds writeCWE-823
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31956
2021-11-03
Microsoft Windows NTFS Privilege Escalation Vulnerability
Microsoft

Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.

CWE-191CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-31755
2021-11-03
Tenda AC11 Router Stack Buffer Overflow Vulnerability
Tenda

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30807
2021-11-03
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30761
2021-11-03
Apple iOS WebKit Memory Corruption Vulnerability
Apple

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-30665
2021-11-03
Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28664
2021-11-03
Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability
Arm

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-28310
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-27562
2021-11-03
Arm Trusted Firmware Out-of-Bounds Write Vulnerability
Arm

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-1732
2021-11-03
Microsoft Win32k Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-9819
2021-11-03
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-9818
2021-11-03
Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Apple

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-27930
2021-11-03
Apple Multiple Products Memory Corruption Vulnerability
Apple

Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16013
2021-11-03
Google Chromium V8 Incorrect Implementation Vulnerabililty
Google

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16010
2021-11-03
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
Google

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-16009
2021-11-03
Google Chromium V8 Type Confusion Vulnerability
Google

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CWE-787 · Out-of-bounds writeCWE-843 · Type confusion
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-15999
2021-11-03
Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-14871
2021-11-03
Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
Oracle

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1380
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1054
2021-11-03
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-1020
2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0986
2021-11-03
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft

Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0968
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0938
2021-11-03
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0878
2021-11-03
Microsoft Edge and Internet Explorer Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0069
2021-11-03
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
MediaTek

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-5544
2021-11-03
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow VulnerabilityRansomware
VMware

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1429
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CWE-416 · Use after freeCWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1367
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-8653
2021-11-03
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0802
2021-11-03
Microsoft Office Memory Corruption VulnerabilityRansomware
Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-0798
2021-11-03
Microsoft Office Memory Corruption Vulnerability
Microsoft

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

CWE-787 · Out-of-bounds write
Refsnvd.nist.gov
Federal remediation due 2022-05-03
Prev2 / 2Next