CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,710
Total CVEs
612
Critical
1,885
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,710)

CVE-2020-28022
9.8

CVE-2020-28022 is a critical heap-based buffer overflow vulnerability in Exim mail servers that allows remote attackers to execute arbitrary code by s...

May 6, 2021
CVE-2020-28024
9.8

CVE-2020-28024 is a critical buffer underwrite vulnerability in Exim mail servers that allows unauthenticated remote attackers to execute arbitrary co...

May 6, 2021
CVE-2019-25042
9.8

CVE-2019-25042 is an out-of-bounds write vulnerability in Unbound DNS resolver versions before 1.9.5, triggered by specially crafted compressed DNS na...

Apr 27, 2021
CVE-2020-23907
9.8

This vulnerability in retdec v3.3 allows attackers to trigger a heap buffer overflow via an out-of-bounds read in the canSplitFunctionOn() function. S...

Apr 21, 2021
CVE-2021-0430
9.8

This vulnerability allows remote code execution via malicious NFC packets without requiring user interaction or additional privileges. An out-of-bound...

Apr 13, 2021
CVE-2021-29998
9.8

CVE-2021-29998 is a heap overflow vulnerability in the DHCP client of Wind River VxWorks operating system. This allows remote attackers to execute arb...

Apr 13, 2021
CVE-2021-26709
9.8

CVE-2021-26709 is a critical stack-based buffer overflow vulnerability in D-Link DSL-320B-D1 routers that allows unauthenticated remote attackers to e...

Apr 7, 2021
CVE-2021-24026
9.8

This vulnerability allows remote code execution via WhatsApp voice calls due to a missing bounds check in the audio decoding pipeline. An attacker cou...

Apr 6, 2021
CVE-2021-30072
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on D-Link DIR-878 routers via a stack-based buffer overflow in the prog....

Apr 2, 2021
CVE-2021-1796
9.8

CVE-2021-1796 is a critical out-of-bounds write vulnerability in iOS and iPadOS that allows remote attackers to execute arbitrary code on affected dev...

Apr 2, 2021
CVE-2021-27804
9.8

CVE-2021-27804 is a critical memory corruption vulnerability in JPEG XL image processing library versions through 0.3.2. It allows attackers to execut...

Mar 2, 2021
CVE-2021-25832
9.8

A heap buffer overflow vulnerability in BMP image processing within ONLYOFFICE DocumentServer allows remote code execution. Attackers can exploit this...

Mar 1, 2021
CVE-2020-11283
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected devices by exploiting a buffer overflow in MKV video file processing....

Feb 22, 2021
CVE-2021-3375
9.8

ActivePresenter 6.1.6 contains a memory corruption vulnerability (CWE-787) that allows attackers to crash the application or execute arbitrary code by...

Feb 15, 2021
CVE-2021-25689
9.8

CVE-2021-25689 is a critical out-of-bounds write vulnerability in Teradici PCoIP soft client that allows remote code execution. Attackers can exploit ...

Feb 11, 2021
CVE-2021-27171
9.8

This vulnerability allows attackers to start a telnet daemon with root privileges on FiberHome HG6245D devices by using specific CLI commands. This en...

Feb 10, 2021
CVE-2020-36244
9.8

CVE-2020-36244 is a critical heap-based buffer overflow vulnerability in GENIVI diagnostic log and trace (DLT) daemon that allows remote attackers to ...

Feb 10, 2021
CVE-2021-26951
9.8

This vulnerability in the calamine Rust crate allows attackers to write arbitrary data to uninitialized heap memory locations, potentially leading to ...

Feb 9, 2021
CVE-2021-25139
9.8

CVE-2021-25139 is a critical stack-based buffer overflow vulnerability in HPE Moonshot Provisioning Manager v1.20 that allows unauthenticated remote a...

Feb 9, 2021
CVE-2020-25782
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected Accfly wireless security cameras via a stack-based bu...

Jan 28, 2021
CVE-2020-25784
9.8

CVE-2020-25784 is an unauthenticated stack-based buffer overflow vulnerability in Accfly Wireless Security IR Camera System 720P. Attackers can remote...

Jan 28, 2021
CVE-2021-25900
9.8

A heap-based buffer overflow vulnerability in the smallvec Rust crate allows attackers to write beyond allocated memory boundaries when using the inse...

Jan 26, 2021
CVE-2020-27539
9.8

This vulnerability is a heap buffer overflow in the custom HTTP parser of the AgentUpdater service in Rostelecom CS-C2SHW IP cameras. It allows remote...

Jan 26, 2021
CVE-2020-11140
9.8

CVE-2020-11140 is a critical memory corruption vulnerability in Qualcomm Snapdragon chipsets that allows out-of-bounds memory access during ALAC (Appl...

Jan 21, 2021
CVE-2020-9144
9.8

CVE-2020-9144 is a critical heap overflow vulnerability in certain Huawei smartphones that allows attackers to execute arbitrary code by exploiting im...

Jan 13, 2021
CVE-2021-0316
9.8

This vulnerability allows remote code execution via Bluetooth without user interaction. An attacker can exploit a missing bounds check in Android's Bl...

Jan 11, 2021
CVE-2020-24027
9.8

CVE-2020-24027 is a critical buffer overflow vulnerability in liblivemedia's RTSP server component. When processing a specially crafted RTSP PLAY comm...

Jan 11, 2021
CVE-2020-36177
9.8

This vulnerability in wolfSSL's RSA-PSS padding implementation allows an out-of-bounds write when processing certain cryptographic operations. Attacke...

Jan 6, 2021
CVE-2020-35895
9.8

CVE-2020-35895 is a memory corruption vulnerability in the Rust stack crate's ArrayVec implementation that allows out-of-bounds writes during element ...

Dec 31, 2020
CVE-2020-35858
9.8

This vulnerability in the prost Rust crate allows attackers to cause stack exhaustion via specially crafted messages, leading to denial of service. In...

Dec 31, 2020
CVE-2020-14224
9.8

CVE-2020-14224 is a critical stack buffer overflow vulnerability in HCL Notes v9 client's MIME message handling. An unauthenticated remote attacker co...

Dec 18, 2020
CVE-2020-20276
9.8

An unauthenticated stack-based buffer overflow vulnerability in uftpd FTP server allows remote attackers to crash the service and potentially execute ...

Dec 18, 2020
CVE-2020-0456
9.8

CVE-2020-0456 is a critical out-of-bounds write vulnerability in Android System-on-Chip (SoC) components that could allow attackers to execute arbitra...

Dec 14, 2020
CVE-2020-0455
9.8

CVE-2020-0455 is a critical out-of-bounds write vulnerability in Android System-on-Chip (SoC) components that could allow attackers to execute arbitra...

Dec 14, 2020
CVE-2020-14268
9.8

A stack buffer overflow vulnerability in HCL Notes client MIME message handling allows unauthenticated remote attackers to crash the client or execute...

Dec 14, 2020
CVE-2020-25111
9.8

CVE-2020-25111 is a critical vulnerability in Contiki's IPv6 stack where insufficient validation of IPv6 header length allows attackers to cause denia...

Dec 11, 2020
CVE-2020-24338
9.8

This vulnerability in picoTCP's DNS implementation allows attackers to send specially crafted DNS responses that trigger out-of-bounds writes, potenti...

Dec 11, 2020
CVE-2020-17438
9.8

This vulnerability in uIP 1.0 allows attackers to write beyond allocated memory buffers by sending specially crafted fragmented IP packets. This can c...

Dec 11, 2020
CVE-2020-13556
9.8

CVE-2020-13556 is a critical out-of-bounds write vulnerability in the OpENer Ethernet/IP server that allows remote code execution via specially crafte...

Dec 11, 2020
CVE-2020-25462
9.8

A heap buffer overflow vulnerability in the Moddable SDK's JavaScript engine allows attackers to execute arbitrary code or cause denial of service. Th...

Dec 4, 2020
CVE-2020-26762
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Edimax IP cameras that allows unauthenticated remote attackers to execute a...

Dec 1, 2020
CVE-2020-25014
9.8

A stack-based buffer overflow vulnerability in the fbwifi_continue.cgi component of Zyxel UTM and VPN gateways allows remote unauthenticated attackers...

Nov 27, 2020
CVE-2020-28578
9.8

CVE-2020-28578 is a critical remote code execution vulnerability in Trend Micro InterScan Web Security Virtual Appliance that allows unauthenticated a...

Nov 18, 2020
CVE-2020-8752
9.8

This vulnerability allows an unauthenticated attacker to write data outside intended memory boundaries in the IPv6 subsystem of Intel Active Managemen...

Nov 12, 2020
CVE-2020-0445
9.8

CVE-2020-0445 is a critical out-of-bounds write vulnerability in Android System-on-Chip (SoC) components that could allow attackers to execute arbitra...

Nov 10, 2020
CVE-2020-0447
9.8

CVE-2020-0447 is a critical out-of-bounds write vulnerability in Android System-on-Chip (SoC) components that could allow attackers to execute arbitra...

Nov 10, 2020
CVE-2020-11153
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting an out-of-bounds memory acc...

Nov 2, 2020
CVE-2020-12830
9.8

This CVE describes multiple stack buffer overflow vulnerabilities in Western Digital My Cloud devices that allow remote attackers to execute arbitrary...

Oct 27, 2020
CVE-2019-8767
9.8

CVE-2019-8767 is a critical heap corruption vulnerability in macOS that allows attackers to execute arbitrary code or cause denial of service by proce...

Oct 27, 2020
CVE-2019-8756
9.8

CVE-2019-8756 is a critical memory corruption vulnerability in libxml2 affecting multiple Apple products. It allows attackers to execute arbitrary cod...

Oct 27, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,710 CVEs classified as CWE-787, with 612 rated critical and 1,885 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free