CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,710
Total CVEs
612
Critical
1,885
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,710)

CVE-2021-43215
9.8

CVE-2021-43215 is a critical memory corruption vulnerability in Microsoft's iSNS Server that allows remote attackers to execute arbitrary code on affe...

Dec 15, 2021
CVE-2021-43527
9.8

CVE-2021-43527 is a critical heap overflow vulnerability in NSS (Network Security Services) that allows remote code execution when processing maliciou...

Dec 8, 2021
CVE-2021-35344
9.8

CVE-2021-35344 is a heap-based buffer overflow vulnerability in tsMuxer v2.6.16 that allows attackers to execute arbitrary code or cause denial of ser...

Dec 3, 2021
CVE-2021-28237
9.8

LibreDWG v0.12.3 contains a heap-buffer overflow vulnerability in the decode_preR13 function that allows attackers to execute arbitrary code or cause ...

Dec 2, 2021
CVE-2021-33265
9.8

CVE-2021-33265 is a critical stack buffer overflow vulnerability in D-Link DIR-809 routers that allows remote attackers to execute arbitrary code or c...

Dec 1, 2021
CVE-2021-33267
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-809 routers via a stack buffer overflow in the formStaticDHCP funct...

Dec 1, 2021
CVE-2021-33269
9.8

CVE-2021-33269 is a critical stack buffer overflow vulnerability in D-Link DIR-809 routers that allows remote attackers to execute arbitrary code via ...

Dec 1, 2021
CVE-2021-33271
9.8

D-Link DIR-809 routers contain a critical stack buffer overflow vulnerability in their web interface that allows remote attackers to execute arbitrary...

Dec 1, 2021
CVE-2021-37022
9.8

This is a critical heap-based buffer overflow vulnerability in Huawei smartphones that allows attackers to escalate privileges to root access. It affe...

Nov 23, 2021
CVE-2021-44143
9.8

A heap overflow vulnerability in mbsync component of isync allows remote code execution when processing malicious email messages from a compromised IM...

Nov 22, 2021
CVE-2021-37592
9.8

This vulnerability allows attackers to evade Suricata's TCP traffic inspection by sending a crafted sequence of TCP segments from a malicious client. ...

Nov 19, 2021
CVE-2021-1975
9.8

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses....

Nov 12, 2021
CVE-2020-23873
9.8

CVE-2020-23873 is a critical heap-buffer overflow vulnerability in pdf2xml v2.0's TextPage::dump function that allows attackers to execute arbitrary c...

Nov 10, 2021
CVE-2020-23877
9.8

CVE-2020-23877 is a critical stack buffer overflow vulnerability in pdf2xml v2.0's getObjectStream component that allows remote attackers to execute a...

Nov 10, 2021
CVE-2021-41036
9.8

CVE-2021-41036 is a critical buffer overflow vulnerability in the Eclipse Paho MQTT C Client library where the client fails to properly validate the r...

Nov 3, 2021
CVE-2020-22079
9.8

This is a critical stack-based buffer overflow vulnerability in Tenda AC-10U routers that allows remote attackers to execute arbitrary code by sending...

Oct 29, 2021
CVE-2021-21748
9.8

CVE-2021-21748 affects ZTE MF971R mobile hotspot devices with two stack-based buffer overflow vulnerabilities. Attackers can exploit these vulnerabili...

Oct 20, 2021
CVE-2021-39275
9.8

CVE-2021-39275 is a critical buffer overflow vulnerability in Apache HTTP Server's ap_escape_quotes() function that could allow remote code execution ...

Sep 16, 2021
CVE-2021-3751
9.8

CVE-2021-3751 is an out-of-bounds write vulnerability in libmobi, a library for handling MOBI eBook files. This vulnerability allows attackers to exec...

Sep 15, 2021
CVE-2021-34344
9.8

This CVE-2021-34344 is a critical stack buffer overflow vulnerability in QNAP's QUSBCam2 software that allows remote attackers to execute arbitrary co...

Sep 10, 2021
CVE-2021-34346
9.8

A stack buffer overflow vulnerability in QNAP NVR Storage Expansion allows attackers to execute arbitrary code on affected devices. This affects QNAP ...

Sep 10, 2021
CVE-2021-1882
9.8

CVE-2021-1882 is a critical memory corruption vulnerability in Apple operating systems that allows an application to gain elevated privileges. This af...

Sep 8, 2021
CVE-2021-1834
9.8

CVE-2021-1834 is an out-of-bounds write vulnerability in macOS that allows a malicious application to execute arbitrary code with kernel privileges. T...

Sep 8, 2021
CVE-2021-30805
9.8

CVE-2021-30805 is a critical memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. Thi...

Sep 8, 2021
CVE-2021-1916
9.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting a buffer underflow in Qualcomm Snapdragon chips...

Sep 8, 2021
CVE-2021-35393
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected devices by exploiting a stack buffer overflow in Real...

Aug 16, 2021
CVE-2021-20314
9.8

A stack buffer overflow vulnerability in libspf2 versions below 1.2.11 allows attackers to cause denial of service or potentially execute arbitrary co...

Aug 12, 2021
CVE-2021-38568
9.8

This vulnerability in Foxit Reader and PhantomPDF allows memory corruption when converting PDF documents to other formats, potentially enabling remote...

Aug 11, 2021
CVE-2021-33485
9.8

CVE-2021-33485 is a critical heap-based buffer overflow vulnerability in CODESYS Control Runtime systems. Successful exploitation could allow remote a...

Aug 3, 2021
CVE-2021-37164
9.8

A stack-based buffer overflow vulnerability in Swisslog Healthcare Nexus Panel's HMI3 Control Panel allows remote attackers to execute arbitrary code ...

Aug 2, 2021
CVE-2021-35522
9.8

A critical buffer overflow vulnerability in Thrift command handlers in IDEMIA biometric devices allows remote attackers to execute arbitrary code, cau...

Jul 22, 2021
CVE-2020-11633
9.8

A stack-based buffer overflow vulnerability in Zscaler Client Connector for Windows allows remote code execution with SYSTEM privileges when connectin...

Jul 15, 2021
CVE-2021-0515
9.8

This vulnerability allows remote code execution through an out-of-bounds write in Android's Factory::CreateStrictFunctionMap function. Attackers can e...

Jul 14, 2021
CVE-2018-25017
9.8

CVE-2018-25017 is a critical heap-based buffer overflow vulnerability in RawSpeed library version 3.1 that allows attackers to execute arbitrary code ...

Jul 1, 2021
CVE-2020-36400
9.8

CVE-2020-36400 is a heap-based buffer overflow vulnerability in ZeroMQ's libzmq library that allows remote attackers to execute arbitrary code or caus...

Jul 1, 2021
CVE-2021-22345
9.8

This CVE describes an input verification vulnerability in Huawei smartphones that allows out-of-bounds memory writes. Attackers can exploit this to po...

Jun 30, 2021
CVE-2021-32988
9.8

This vulnerability allows an attacker to execute arbitrary code on systems running vulnerable versions of FATEK Automation WinProladder software. It a...

Jun 29, 2021
CVE-2021-34813
9.8

This vulnerability in Matrix libolm allows a malicious Matrix homeserver to crash a client via a stack-based buffer overflow in the olm_pk_decrypt fun...

Jun 16, 2021
CVE-2021-27410
9.8

This critical vulnerability allows attackers to write data beyond intended memory boundaries in Welch Allyn medical device management tools, potential...

Jun 11, 2021
CVE-2021-0474
9.8

This critical vulnerability in Android's Bluetooth AVRCP protocol allows remote attackers to execute arbitrary code without user interaction by sendin...

Jun 11, 2021
CVE-2020-23321
9.8

This is a critical heap buffer overflow vulnerability in JerryScript's UTF-8 string parsing code. Attackers can exploit this to execute arbitrary code...

Jun 10, 2021
CVE-2020-23323
9.8

CVE-2020-23323 is a critical heap buffer overflow vulnerability in JerryScript's regular expression parser that allows remote code execution. Attacker...

Jun 10, 2021
CVE-2020-23306
9.8

CVE-2020-23306 is a critical stack-based buffer overflow vulnerability in JerryScript's regular expression engine that allows remote code execution. A...

Jun 10, 2021
CVE-2021-33833
9.8

CVE-2021-33833 is a critical stack-based buffer overflow vulnerability in ConnMan's DNS proxy component. Attackers can exploit this by sending special...

Jun 9, 2021
CVE-2020-11176
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via heap overflow during IPSec certificate validation ...

Jun 9, 2021
CVE-2020-11182
9.8

This vulnerability allows remote code execution via heap overflow in Qualcomm Snapdragon chipsets when parsing NAL headers in video processing. It aff...

Jun 9, 2021
CVE-2021-30188
9.8

CVE-2021-30188 is a critical stack-based buffer overflow vulnerability in CODESYS V2 runtime systems. It allows remote attackers to execute arbitrary ...

May 25, 2021
CVE-2018-25011
9.8

A heap-based buffer overflow vulnerability in libwebp's PutLE16() function allows attackers to execute arbitrary code or cause denial of service. This...

May 21, 2021
CVE-2021-31755
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC11 routers via a stack buffer overflow in the /goform/setmac endpoint....

May 7, 2021
CVE-2021-31757
9.8

This critical vulnerability in Tenda AC11 routers allows remote attackers to execute arbitrary code via a stack buffer overflow in the setVLAN form ha...

May 7, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,710 CVEs classified as CWE-787, with 612 rated critical and 1,885 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free