CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,710
Total CVEs
612
Critical
1,885
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,710)

CVE-2019-8712
9.8

CVE-2019-8712 is a critical memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with syste...

Oct 27, 2020
CVE-2019-8716
9.8

CVE-2019-8716 is a critical memory corruption vulnerability in macOS that allows an application to execute arbitrary code with system privileges. This...

Oct 27, 2020
CVE-2020-24646
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected HPE Intelligent Management Center (iMC) systems via a stack-based buf...

Oct 19, 2020
CVE-2019-19513
9.8

CVE-2019-19513 is an out-of-bounds write vulnerability in the BASSMIDI plugin for Un4seen BASS Audio Library on Windows. Successful exploitation allow...

Oct 16, 2020
CVE-2020-1907
9.8

A stack overflow vulnerability in WhatsApp's RTP Extension header parsing allows remote attackers to execute arbitrary code on affected devices. This ...

Oct 6, 2020
CVE-2020-7465
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through memory corruption in MPD's L2TP implementation...

Oct 6, 2020
CVE-2020-26537
9.8

CVE-2020-26537 is a critical memory corruption vulnerability in Foxit Reader and PhantomPDF that allows attackers to execute arbitrary code by exploit...

Oct 2, 2020
CVE-2020-13995
9.8

CVE-2020-13995 is a critical buffer overflow vulnerability in the U.S. Air Force Sensor Data Management System's extract75 component that allows remot...

Sep 25, 2020
CVE-2020-0354
9.8

This critical Bluetooth vulnerability in Android 11 allows attackers to execute arbitrary code remotely without user interaction. It affects all Andro...

Sep 18, 2020
CVE-2020-25489
9.8

CVE-2020-25489 is a heap overflow vulnerability in Sqreen PyMiniRacer that allows remote attackers to potentially exploit heap corruption. This could ...

Sep 17, 2020
CVE-2020-0123
9.8

This CVE describes an out-of-bounds write vulnerability in Android System-on-Chip (SoC) components due to incorrect bounds checking. It allows attacke...

Sep 17, 2020
CVE-2020-0278
9.8

CVE-2020-0278 is an out-of-bounds write vulnerability in Android System-on-Chip (SoC) components that could allow attackers to execute arbitrary code ...

Sep 17, 2020
CVE-2020-0380
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. It affects Android versions...

Sep 17, 2020
CVE-2020-14315
9.8

CVE-2020-14315 is a critical memory corruption vulnerability in bspatch (part of bsdiff tools) that allows attackers to write outside allocated buffer...

Sep 16, 2020
CVE-2020-25412
9.8

CVE-2020-25412 is a critical out-of-bounds write vulnerability in gnuplot's com_line() function that allows arbitrary code execution via specially cra...

Sep 16, 2020
CVE-2020-25278
9.8

This critical vulnerability in Samsung's Quram image codec library allows attackers to execute arbitrary code by sending specially crafted JPEG images...

Sep 11, 2020
CVE-2020-1891
9.8

This vulnerability in WhatsApp allows attackers to trigger an out-of-bounds write via a user-controlled parameter during video calls. Successful explo...

Sep 3, 2020
CVE-2020-25052
9.8

This vulnerability in Samsung mobile devices with Exynos9830 chipsets allows attackers to execute arbitrary code or cause denial of service through me...

Aug 31, 2020
CVE-2020-14934
9.8

CVE-2020-14934 is a critical buffer overflow vulnerability in Contiki-NG's SNMP agent that allows remote attackers to write arbitrary data beyond allo...

Aug 18, 2020
CVE-2020-14936
9.8

A critical buffer overflow vulnerability in Contiki-NG's SNMP agent allows remote attackers to overwrite memory regions beyond allocated buffers by se...

Aug 18, 2020
CVE-2019-1212
9.8

A memory corruption vulnerability in Windows Server DHCP service allows remote unauthenticated attackers to send specially crafted packets that could ...

Aug 14, 2019
CVE-2019-0736
9.8

This is a critical memory corruption vulnerability in Windows DHCP client that allows remote code execution. An attacker can exploit it by sending spe...

Aug 14, 2019
CVE-2018-1160
EPSS 89.7% 9.8

CVE-2018-1160 is a critical vulnerability in Netatalk that allows remote unauthenticated attackers to execute arbitrary code due to an out-of-bounds w...

Dec 20, 2018
CVE-2024-7024
9.6

This vulnerability in Chrome's V8 JavaScript engine allows an attacker to escape the browser sandbox via a malicious HTML page. All users running affe...

Sep 23, 2024
CVE-2024-7519
9.6

This vulnerability allows memory corruption through insufficient checks in graphics shared memory processing, potentially enabling sandbox escape. It ...

Aug 6, 2024
CVE-2024-6779
9.6

This vulnerability in Chrome's V8 JavaScript engine allows out-of-bounds memory access that could enable sandbox escape. Attackers could potentially e...

Jul 16, 2024
CVE-2024-3157
9.6

This vulnerability allows a remote attacker who has already compromised Chrome's GPU process to perform a sandbox escape via specific UI gestures, pot...

Apr 10, 2024
CVE-2022-4920
9.6

This vulnerability is a heap buffer overflow in Chrome's Blink rendering engine that allows a remote attacker to potentially escape the browser sandbo...

Jul 29, 2023
CVE-2021-45638
9.6

This CVE describes a critical stack-based buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers...

Dec 26, 2021
CVE-2021-38013
9.6

This vulnerability allows a remote attacker who has already compromised a Chrome WebUI renderer process to exploit a heap buffer overflow in ChromeOS ...

Dec 23, 2021
CVE-2021-37981
9.6

CVE-2021-37981 is a heap buffer overflow vulnerability in Chrome's Skia graphics engine that allows an attacker who has already compromised the render...

Nov 2, 2021
CVE-2021-21154
9.6

This vulnerability is a heap buffer overflow in Chrome's Tab Strip component that allows an attacker who has already compromised the renderer process ...

Feb 22, 2021
CVE-2020-16024
9.6

This vulnerability is a heap buffer overflow in Google Chrome's UI component that allows a remote attacker who has already compromised the renderer pr...

Jan 8, 2021
CVE-2020-16010
9.6

This vulnerability is a heap buffer overflow in the UI component of Google Chrome on Android. It allows a remote attacker who has already compromised ...

Nov 3, 2020
CVE-2020-15999
9.6

This CVE describes a heap buffer overflow vulnerability in the Freetype font rendering library used by Google Chrome. A remote attacker could exploit ...

Nov 3, 2020
CVE-2026-1678
9.4

This vulnerability in Zephyr RTOS's DNS resolver allows an out-of-bounds write when processing malicious DNS responses. Attackers can exploit this to ...

Mar 5, 2026
CVE-2025-1268
9.4

This CVE describes an out-of-bounds write vulnerability in multiple Canon printer drivers that could allow an attacker to execute arbitrary code with ...

Mar 31, 2025
CVE-2026-20407
9.3

This CVE describes a privilege escalation vulnerability in MediaTek wlan STA drivers where missing bounds checks allow local attackers to gain elevate...

Feb 2, 2026
CVE-2025-41238
9.3

A heap-overflow vulnerability in VMware's PVSCSI controller allows local administrative users within a virtual machine to execute code on the host sys...

Jul 15, 2025
CVE-2025-41236
9.3

This CVE describes an integer-overflow vulnerability in VMware's VMXNET3 virtual network adapter that allows a malicious actor with local administrati...

Jul 15, 2025
CVE-2020-11210
9.3

This vulnerability allows memory corruption in the RPM region due to improper XPU configuration in Qualcomm Snapdragon chipsets. It affects devices us...

Apr 7, 2021
CVE-2025-27807
9.1

A critical vulnerability in multiple Samsung Exynos processors allows attackers to execute arbitrary code or cause denial of service via malformed NAS...

Jan 5, 2026
CVE-2025-15359
9.1

This vulnerability in Delta Electronics DVP-12SE11T PLC modules allows attackers to write data beyond allocated memory boundaries, potentially leading...

Dec 30, 2025
CVE-2025-23097
9.1

CVE-2025-23097 is a critical memory corruption vulnerability in Samsung's Exynos 1380 mobile processor where missing length validation allows attacker...

Jun 3, 2025
CVE-2025-23099
9.1

A memory corruption vulnerability in Samsung Exynos 1480 and 2400 mobile processors allows attackers to write data beyond allocated memory boundaries....

Jun 2, 2025
CVE-2025-27105
9.1

This vulnerability in Vyper smart contract language allows out-of-bounds array access when using augmented assignment operators on dynamic arrays. Att...

Feb 21, 2025
CVE-2025-24154
9.1

This CVE describes an out-of-bounds write vulnerability in Apple operating systems that could allow an attacker to cause system crashes or corrupt ker...

Jan 27, 2025
CVE-2021-47354
9.1

This vulnerability in the Linux kernel's DRM scheduler could allow data corruption when GPU jobs are terminated prematurely. It affects systems using ...

May 21, 2024
CVE-2023-52369
9.1

A stack overflow vulnerability in the NFC module allows attackers to execute arbitrary code or cause denial of service. This affects Huawei devices ru...

Feb 18, 2024
CVE-2023-47456
9.1

Tenda AX1806 routers running firmware V1.0.0.1 contain a stack overflow vulnerability in the wireless repeater configuration function. This allows rem...

Nov 7, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,710 CVEs classified as CWE-787, with 612 rated critical and 1,885 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free