Vulnerabilities (CVE)

Filtered by CWE-787
Total 11670 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-54627 1 Huawei 1 Harmonyos 2025-08-20 N/A 8.8 HIGH
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-27907 1 Siemens 1 Simcenter Femap 2025-08-20 N/A 7.8 HIGH
A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22051)
CVE-2025-40762 1 Siemens 1 Simcenter Femap 2025-08-20 N/A 7.8 HIGH
A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted STP file. This could allow an attacker to execute code in the context of the current process.(ZDI-CAN-26692)
CVE-2025-4877 2025-08-20 N/A 4.5 MEDIUM
There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases the bin_to_base64() function can experience an integer overflow leading to a memory under allocation, when that happens it's possible that the program perform out of bounds write leading to a heap corruption. This issue affects only 32-bits builds of libssh.
CVE-2025-0144 1 Zoom 7 Meeting Software Development Kit, Rooms, Rooms Controller and 4 more 2025-08-20 N/A 3.1 LOW
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
CVE-2025-2900 1 Ibm 1 Semeru Runtime 2025-08-19 N/A 7.5 HIGH
IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
CVE-2025-7675 1 Autodesk 16 3ds Max, Advance Steel, Autocad and 13 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2025-7497 1 Autodesk 16 3ds Max, Advance Steel, Autocad and 13 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2025-6637 1 Autodesk 16 3ds Max, Advance Steel, Autocad and 13 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2025-6633 1 Autodesk 1 3ds Max 2025-08-19 N/A 7.8 HIGH
A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2025-6631 1 Autodesk 16 3ds Max, Advance Steel, Autocad and 13 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVE-2025-2497 1 Autodesk 1 Revit 2025-08-19 N/A 7.8 HIGH
A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-1660 1 Autodesk 1 Navisworks 2025-08-19 N/A 7.8 HIGH
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-1656 1 Autodesk 1 Revit 2025-08-19 N/A 7.8 HIGH
A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
CVE-2025-1651 1 Autodesk 9 Advance Steel, Autocad, Autocad Architecture and 6 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
CVE-2025-53705 2025-08-19 N/A 7.8 HIGH
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-21461 1 Qualcomm 48 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 45 more 2025-08-19 N/A 7.8 HIGH
Memory corruption when programming registers through virtual CDM.
CVE-2025-1430 1 Autodesk 9 Advance Steel, Autocad, Autocad Architecture and 6 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-1429 1 Autodesk 9 Advance Steel, Autocad, Autocad Architecture and 6 more 2025-08-19 N/A 7.8 HIGH
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
CVE-2025-1277 1 Autodesk 1 Revit 2025-08-19 N/A 7.8 HIGH
A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.