CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,626
Total CVEs
600
Critical
1,813
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 293
2 Linux 227
3 Tenda 189
4 Adobe 186
5 Apple 161
6 Debian 130
7 Fedoraproject 87
8 Samsung 77
9 Siemens 67
10 Dlink 59

All Out-of-bounds Write CVEs (2,626)

CVE-2025-24201
KEV 10.0

This critical vulnerability allows malicious web content to break out of the Web Content sandbox via an out-of-bounds write issue, potentially enablin...

Mar 11, 2025
CVE-2022-43604
10.0

CVE-2022-43604 is a critical out-of-bounds write vulnerability in the OpENer EtherNet/IP stack that allows remote attackers to crash servers or execut...

Mar 16, 2023
CVE-2022-30292
10.0

CVE-2022-30292 is a critical heap-based buffer overflow vulnerability in SQUIRREL 3.2's sqbaselib.cpp due to missing sq_reservestack calls. This allow...

May 4, 2022
CVE-2020-14871
10.0

This is a critical buffer overflow vulnerability (CWE-787) in Oracle Solaris's Pluggable Authentication Module (PAM) that allows unauthenticated remot...

Oct 21, 2020
CVE-2026-2792
9.8

Memory safety vulnerabilities in Mozilla Firefox and Thunderbird could allow memory corruption attacks. With sufficient effort, attackers could exploi...

Feb 24, 2026
CVE-2019-25362
9.8

CVE-2019-25362 is a critical buffer overflow vulnerability in WMV to AVI MPEG DVD WMV Convertor 4.6.1217 that allows remote attackers to execute arbit...

Feb 18, 2026
CVE-2026-20418
9.8

CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote attackers to execute arbitrary co...

Feb 2, 2026
CVE-2026-24832
9.8

CVE-2026-24832 is an out-of-bounds write vulnerability in ixray-team's ixray-1.6-stcop software that allows attackers to write data beyond allocated m...

Jan 27, 2026
CVE-2025-15467
9.8

This vulnerability allows attackers to trigger a stack buffer overflow by sending maliciously crafted CMS AuthEnvelopedData messages with oversized IV...

Jan 27, 2026
CVE-2021-47785
9.8

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote attackers to execute arbitrary co...

Jan 16, 2026
CVE-2021-47781
9.8

CVE-2021-47781 is a critical buffer overflow vulnerability in Cmder Console Emulator version 1.3.18 that allows attackers to cause denial of service b...

Jan 15, 2026
CVE-2021-47774
9.8

Kingdia CD Extractor 3.0.2 contains a critical buffer overflow vulnerability in its registration name field that allows remote attackers to execute ar...

Jan 15, 2026
CVE-2021-47772
9.8

CVE-2021-47772 is a critical buffer overflow vulnerability in 10-Strike Network Inventory Explorer Pro that allows remote code execution via malicious...

Jan 15, 2026
CVE-2026-22852
9.8

A heap buffer overflow vulnerability in FreeRDP allows malicious RDP servers to trigger memory corruption and crash FreeRDP clients. This affects all ...

Jan 14, 2026
CVE-2026-22853
9.8

CVE-2026-22853 is a critical heap buffer overflow vulnerability in FreeRDP's RDPEAR component that allows attackers to execute arbitrary code or cause...

Jan 14, 2026
CVE-2026-22184
9.8

This CVE describes a global buffer overflow vulnerability in zlib's untgz utility when processing excessively long archive names via command line. The...

Jan 7, 2026
CVE-2025-14733
KEV EPSS 43.2% 9.8

A critical out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected s...

Dec 19, 2025
CVE-2025-62863
9.8

This vulnerability allows an attacker to perform an out-of-bounds write in the PCIe driver's S-EL0 address space via a malformed SMC call to the UEFI-...

Dec 16, 2025
CVE-2025-62864
9.8

This vulnerability allows attackers to execute arbitrary code in the UEFI-MM Secure Partition context through an out-of-bounds write via a malformed S...

Dec 16, 2025
CVE-2025-66590
9.8

This critical vulnerability in AzeoTech DAQFactory allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary...

Dec 11, 2025
CVE-2025-36937
9.8

This critical vulnerability in Android's audio decoder allows remote attackers to execute arbitrary code without user interaction by exploiting an out...

Dec 11, 2025
CVE-2025-64657
9.8

A stack-based buffer overflow vulnerability in Azure Application Gateway allows unauthorized attackers to execute arbitrary code with elevated privile...

Nov 26, 2025
CVE-2025-65084
9.8

An Out-of-Bounds Write vulnerability in Ashlar-Vellum CAD software allows attackers to execute arbitrary code or disclose sensitive information by sen...

Nov 25, 2025
CVE-2025-11624
9.8

This CVE describes a stack buffer overflow vulnerability in wolfSSH's SFTP server when processing malicious packets with oversized handles. Attackers ...

Oct 21, 2025
CVE-2025-9242
KEV EPSS 61.6% 9.8

An out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected systems. ...

Sep 17, 2025
CVE-2025-9809
9.8

This vulnerability allows remote attackers to execute arbitrary code by providing a specially crafted .cue file with an overly long file path. When pr...

Sep 1, 2025
CVE-2025-43237
9.8

This critical vulnerability in macOS allows an application to write data beyond allocated memory boundaries, potentially leading to system crashes or ...

Jul 30, 2025
CVE-2025-43209
9.8

This is a critical out-of-bounds memory access vulnerability in Apple's Safari browser across multiple Apple operating systems. Processing malicious w...

Jul 30, 2025
CVE-2025-20682
9.8

This vulnerability in MediaTek wlan AP driver allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated system ...

Jul 8, 2025
CVE-2025-20684
9.8

This CVE describes a critical out-of-bounds write vulnerability in MediaTek's WLAN AP driver. An attacker with local user privileges can exploit this ...

Jul 8, 2025
CVE-2025-49709
9.8

This vulnerability in Firefox allows memory corruption through certain canvas operations, potentially enabling remote code execution. It affects all F...

Jun 11, 2025
CVE-2025-2474
9.8

CVE-2025-2474 is a critical out-of-bounds write vulnerability in the PCX image codec in QNX SDP that allows unauthenticated attackers to cause denial-...

Jun 10, 2025
CVE-2025-2146
9.8

A buffer overflow vulnerability in the WebService Authentication processing of Canon multifunction printers and laser printers allows network attacker...

May 26, 2025
CVE-2025-45789
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers via a buffer overflow in the setParentalRules function...

May 8, 2025
CVE-2025-45797
9.8

This CVE describes a critical buffer overflow vulnerability in TOTOlink A950RG routers. Attackers can exploit it by sending specially crafted requests...

May 8, 2025
CVE-2025-45787
9.8

CVE-2025-45787 is a critical buffer overflow vulnerability in TOTOLINK A3100R routers that allows remote attackers to execute arbitrary code by sendin...

May 8, 2025
CVE-2025-45841
9.8

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers by exploiting a stack overflow in the setSmsCf...

May 8, 2025
CVE-2025-31200
KEV 9.8

This is a critical memory corruption vulnerability in Apple's media processing that allows remote code execution via malicious audio streams. Attacker...

Apr 16, 2025
CVE-2025-20654
9.8

This critical vulnerability in MediaTek wlan service allows remote attackers to execute arbitrary code without authentication or user interaction. It ...

Apr 7, 2025
CVE-2025-24273
9.8

This CVE describes a critical out-of-bounds write vulnerability in macOS kernel memory that allows an application to cause system crashes or corrupt k...

Mar 31, 2025
CVE-2025-29384
EPSS 14.6% 9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the wanMTU parameter. Atta...

Mar 14, 2025
CVE-2025-29386
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the web interface. Attacke...

Mar 14, 2025
CVE-2025-29031
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a buffer overflow in the fromAddressNat function. Attack...

Mar 14, 2025
CVE-2025-29029
9.8

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetSp...

Mar 14, 2025
CVE-2025-20646
9.8

This critical vulnerability in MediaTek WLAN AP firmware allows remote attackers to execute arbitrary code without authentication or user interaction....

Mar 3, 2025
CVE-2025-1744
9.8

CVE-2025-1744 is an out-of-bounds write vulnerability in radare2 that allows heap-based buffer over-read or buffer overflow. This affects all users ru...

Feb 28, 2025
CVE-2025-25664
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack overflow in the shareSpeed parameter...

Feb 20, 2025
CVE-2025-26508
9.8

This vulnerability allows attackers to execute arbitrary code and gain elevated privileges on affected HP printers by sending malicious PostScript pri...

Feb 14, 2025
CVE-2025-25742
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in D-Link DIR-853 routers that allows remote attackers to execute arbitrary co...

Feb 12, 2025
CVE-2025-25744
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-853 A1 routers by exploiting a stack-based buffer overflow in the S...

Feb 12, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,626 CVEs classified as CWE-787, with 600 rated critical and 1,813 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free