CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,701)
This critical vulnerability allows malicious web content to break out of the Web Content sandbox via an out-of-bounds write issue, potentially enablin...
Mar 11, 2025CVE-2022-43604 is a critical out-of-bounds write vulnerability in the OpENer EtherNet/IP stack that allows remote attackers to crash servers or execut...
Mar 16, 2023CVE-2022-30292 is a critical heap-based buffer overflow vulnerability in SQUIRREL 3.2's sqbaselib.cpp due to missing sq_reservestack calls. This allow...
May 4, 2022This is a critical buffer overflow vulnerability (CWE-787) in Oracle Solaris's Pluggable Authentication Module (PAM) that allows unauthenticated remot...
Oct 21, 2020Memory safety vulnerabilities in Mozilla Firefox and Thunderbird could allow memory corruption attacks. With sufficient effort, attackers could exploi...
Feb 24, 2026CVE-2019-25362 is a critical buffer overflow vulnerability in WMV to AVI MPEG DVD WMV Convertor 4.6.1217 that allows remote attackers to execute arbit...
Feb 18, 2026CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote attackers to execute arbitrary co...
Feb 2, 2026CVE-2026-24832 is an out-of-bounds write vulnerability in ixray-team's ixray-1.6-stcop software that allows attackers to write data beyond allocated m...
Jan 27, 2026This vulnerability allows attackers to trigger a stack buffer overflow by sending maliciously crafted CMS AuthEnvelopedData messages with oversized IV...
Jan 27, 2026Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote attackers to execute arbitrary co...
Jan 16, 2026CVE-2021-47781 is a critical buffer overflow vulnerability in Cmder Console Emulator version 1.3.18 that allows attackers to cause denial of service b...
Jan 15, 2026Kingdia CD Extractor 3.0.2 contains a critical buffer overflow vulnerability in its registration name field that allows remote attackers to execute ar...
Jan 15, 2026CVE-2021-47772 is a critical buffer overflow vulnerability in 10-Strike Network Inventory Explorer Pro that allows remote code execution via malicious...
Jan 15, 2026A heap buffer overflow vulnerability in FreeRDP allows malicious RDP servers to trigger memory corruption and crash FreeRDP clients. This affects all ...
Jan 14, 2026CVE-2026-22853 is a critical heap buffer overflow vulnerability in FreeRDP's RDPEAR component that allows attackers to execute arbitrary code or cause...
Jan 14, 2026This CVE describes a global buffer overflow vulnerability in zlib's untgz utility when processing excessively long archive names via command line. The...
Jan 7, 2026A critical out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected s...
Dec 19, 2025This vulnerability allows an attacker to perform an out-of-bounds write in the PCIe driver's S-EL0 address space via a malformed SMC call to the UEFI-...
Dec 16, 2025This vulnerability allows attackers to execute arbitrary code in the UEFI-MM Secure Partition context through an out-of-bounds write via a malformed S...
Dec 16, 2025This critical vulnerability in AzeoTech DAQFactory allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary...
Dec 11, 2025This critical vulnerability in Android's audio decoder allows remote attackers to execute arbitrary code without user interaction by exploiting an out...
Dec 11, 2025A stack-based buffer overflow vulnerability in Azure Application Gateway allows unauthorized attackers to execute arbitrary code with elevated privile...
Nov 26, 2025An Out-of-Bounds Write vulnerability in Ashlar-Vellum CAD software allows attackers to execute arbitrary code or disclose sensitive information by sen...
Nov 25, 2025This CVE describes a stack buffer overflow vulnerability in wolfSSH's SFTP server when processing malicious packets with oversized handles. Attackers ...
Oct 21, 2025An out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected systems. ...
Sep 17, 2025This vulnerability allows remote attackers to execute arbitrary code by providing a specially crafted .cue file with an overly long file path. When pr...
Sep 1, 2025This critical vulnerability in macOS allows an application to write data beyond allocated memory boundaries, potentially leading to system crashes or ...
Jul 30, 2025This is a critical out-of-bounds memory access vulnerability in Apple's Safari browser across multiple Apple operating systems. Processing malicious w...
Jul 30, 2025This vulnerability in MediaTek wlan AP driver allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated system ...
Jul 8, 2025This CVE describes a critical out-of-bounds write vulnerability in MediaTek's WLAN AP driver. An attacker with local user privileges can exploit this ...
Jul 8, 2025This vulnerability in Firefox allows memory corruption through certain canvas operations, potentially enabling remote code execution. It affects all F...
Jun 11, 2025CVE-2025-2474 is a critical out-of-bounds write vulnerability in the PCX image codec in QNX SDP that allows unauthenticated attackers to cause denial-...
Jun 10, 2025A buffer overflow vulnerability in the WebService Authentication processing of Canon multifunction printers and laser printers allows network attacker...
May 26, 2025This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers via a buffer overflow in the setParentalRules function...
May 8, 2025This CVE describes a critical buffer overflow vulnerability in TOTOlink A950RG routers. Attackers can exploit it by sending specially crafted requests...
May 8, 2025CVE-2025-45787 is a critical buffer overflow vulnerability in TOTOLINK A3100R routers that allows remote attackers to execute arbitrary code by sendin...
May 8, 2025This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers by exploiting a stack overflow in the setSmsCf...
May 8, 2025This is a critical memory corruption vulnerability in Apple's media processing that allows remote code execution via malicious audio streams. Attacker...
Apr 16, 2025This critical vulnerability in MediaTek wlan service allows remote attackers to execute arbitrary code without authentication or user interaction. It ...
Apr 7, 2025This CVE describes a critical out-of-bounds write vulnerability in macOS kernel memory that allows an application to cause system crashes or corrupt k...
Mar 31, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the wanMTU parameter. Atta...
Mar 14, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the web interface. Attacke...
Mar 14, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a buffer overflow in the fromAddressNat function. Attack...
Mar 14, 2025A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetSp...
Mar 14, 2025This critical vulnerability in MediaTek WLAN AP firmware allows remote attackers to execute arbitrary code without authentication or user interaction....
Mar 3, 2025CVE-2025-1744 is an out-of-bounds write vulnerability in radare2 that allows heap-based buffer over-read or buffer overflow. This affects all users ru...
Feb 28, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack overflow in the shareSpeed parameter...
Feb 20, 2025This vulnerability allows attackers to execute arbitrary code and gain elevated privileges on affected HP printers by sending malicious PostScript pri...
Feb 14, 2025This CVE describes a critical stack-based buffer overflow vulnerability in D-Link DIR-853 routers that allows remote attackers to execute arbitrary co...
Feb 12, 2025This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-853 A1 routers by exploiting a stack-based buffer overflow in the S...
Feb 12, 2025About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,701 CVEs classified as CWE-787, with 611 rated critical and 1,877 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free