CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,747
Total CVEs
636
Critical
1,898
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 318
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 166
6 Debian 141
7 Fedoraproject 97
8 Samsung 77
9 Siemens 74
10 Mozilla 60

All Out-of-bounds Write CVEs (2,747)

CVE-2024-5499
8.8

This vulnerability is an out-of-bounds write in Chrome's Streams API that allows remote attackers to execute arbitrary code within the browser's sandb...

May 30, 2024
CVE-2024-23948
8.8

This vulnerability allows an attacker to execute arbitrary code or cause a denial of service by providing a malicious .msh file to libigl. It affects ...

May 28, 2024
CVE-2024-23950
8.8

This vulnerability allows an attacker to execute arbitrary code or cause a denial of service by providing a malicious .msh file to libigl's readMSH fu...

May 28, 2024
CVE-2024-4761
8.8

This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code by tricking users...

May 14, 2024
CVE-2021-34947
8.8

This is a critical remote code execution vulnerability in NETGEAR R7800 routers that allows network-adjacent attackers to execute arbitrary code as ro...

May 7, 2024
CVE-2023-34307
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite. Att...

May 3, 2024
CVE-2023-34295
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro by tricking user...

May 3, 2024
CVE-2023-34297
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro by tricking user...

May 3, 2024
CVE-2023-34293
8.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...

May 3, 2024
CVE-2023-32133
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K image files in Sante DICOM Viewer Pr...

May 3, 2024
CVE-2023-32131
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro. Attackers can e...

May 3, 2024
CVE-2024-29218
8.8

This CVE describes an out-of-bounds write vulnerability in Keyence KV STUDIO, KV REPLAY VIEWER, and VT5-WX15/WX12 industrial software. Attackers can e...

Apr 15, 2024
CVE-2024-20039
8.8

This CVE describes a critical out-of-bounds write vulnerability in MediaTek modem protocol that allows remote code execution without user interaction ...

Apr 1, 2024
CVE-2024-2614
8.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Mar 19, 2024
CVE-2024-23226
8.8

This is a memory corruption vulnerability (CWE-787) in Apple's web content processing components that could allow arbitrary code execution when proces...

Mar 8, 2024
CVE-2024-2173
8.8

This vulnerability allows a remote attacker to perform out-of-bounds memory access in Chrome's V8 JavaScript engine via a crafted HTML page. This coul...

Mar 6, 2024
CVE-2024-1669
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory access in Chrome's Blink rendering engine by tricking users into visiting a...

Feb 21, 2024
CVE-2022-23092
8.8

CVE-2022-23092 is a memory corruption vulnerability in lib9p's RWALK message handling that allows a malicious bhyve guest kernel to overwrite host mem...

Feb 15, 2024
CVE-2022-23087
8.8

CVE-2022-23087 is a memory corruption vulnerability in the e1000 network adapter emulation in bhyve hypervisor. A malicious guest VM can overwrite hos...

Feb 15, 2024
CVE-2024-25447
8.8

A heap buffer overflow vulnerability in imlib2's image parsing function allows attackers to execute arbitrary code or crash applications by processing...

Feb 9, 2024
CVE-2024-0745
8.8

A stack buffer overflow vulnerability in Firefox's WebAudio OscillatorNode could allow attackers to cause a crash or potentially execute arbitrary cod...

Jan 23, 2024
CVE-2024-23214
8.8

This CVE describes memory corruption vulnerabilities in Apple's WebKit browser engine that could allow arbitrary code execution when processing malici...

Jan 23, 2024
CVE-2024-0517
8.8

This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption via ...

Jan 16, 2024
CVE-2024-0519
8.8

This vulnerability allows a remote attacker to exploit heap corruption in Google Chrome's V8 JavaScript engine via a crafted HTML page. Attackers coul...

Jan 16, 2024
CVE-2023-7024
8.8

This vulnerability is a heap buffer overflow in WebRTC within Google Chrome that allows remote attackers to potentially exploit heap corruption via a ...

Dec 21, 2023
CVE-2023-6873
8.8

CVE-2023-6873 is a memory corruption vulnerability in Firefox that could allow an attacker to execute arbitrary code on a victim's system. It affects ...

Dec 19, 2023
CVE-2023-6856
8.8

This CVE describes a heap buffer overflow vulnerability in Firefox's WebGL DrawElementsInstanced method when used with Mesa VM driver. An attacker cou...

Dec 19, 2023
CVE-2023-6858
8.8

CVE-2023-6858 is a heap buffer overflow vulnerability in Firefox's nsTextFragment component caused by insufficient out-of-memory handling. Attackers c...

Dec 19, 2023
CVE-2023-6861
8.8

This vulnerability allows remote attackers to execute arbitrary code via a heap buffer overflow in Firefox's nsWindow::PickerOpen method when running ...

Dec 19, 2023
CVE-2023-42917
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....

Nov 30, 2023
CVE-2023-48106
8.8

A buffer overflow vulnerability in zlib-ng's minizip-ng library allows attackers to execute arbitrary code by providing a specially crafted file to th...

Nov 22, 2023
CVE-2023-6212
8.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Nov 21, 2023
CVE-2023-47004
8.8

This is an authenticated buffer overflow vulnerability in RedisGraph that allows remote code execution. Attackers with valid authentication can exploi...

Nov 6, 2023
CVE-2023-44398
8.8

CVE-2023-44398 is an out-of-bounds write vulnerability in Exiv2 v0.28.0 that allows remote code execution when processing a malicious image file. Atta...

Nov 6, 2023
CVE-2023-46602
8.8

CVE-2023-46602 is a stack-based buffer overflow vulnerability in the icFixXml function of International Color Consortium's DemoIccMAX library. This al...

Oct 23, 2023
CVE-2023-5474
8.8

A heap buffer overflow vulnerability in Chrome's PDF renderer allows remote attackers to potentially exploit heap corruption via a crafted PDF file. U...

Oct 11, 2023
CVE-2023-43641
8.8

CVE-2023-43641 is a critical out-of-bounds array access vulnerability in libcue that allows remote code execution. Attackers can exploit this by trick...

Oct 9, 2023
CVE-2023-35684
8.8

This vulnerability allows a paired Bluetooth device to execute arbitrary code on an Android device without user interaction. It affects Android device...

Sep 11, 2023
CVE-2020-19318
8.8

This CVE describes a buffer overflow vulnerability in D-Link DIR-605L routers that allows authenticated attackers to execute arbitrary code by sending...

Sep 11, 2023
CVE-2023-4584
8.8

CVE-2023-4584 is a memory corruption vulnerability in Mozilla products that could allow attackers to execute arbitrary code on affected systems. This ...

Sep 11, 2023
CVE-2023-40857
8.8

A buffer overflow vulnerability in VirusTotal YARA v4.3.2 allows remote attackers to execute arbitrary code via the yr_execute_cod function in the exe...

Aug 28, 2023
CVE-2021-40263
8.8

A heap overflow vulnerability in FreeImage 1.18.0 allows attackers to execute arbitrary code or cause denial of service by processing specially crafte...

Aug 22, 2023
CVE-2021-40265
8.8

CVE-2021-40265 is a heap overflow vulnerability in FreeImage's JPEG plugin that allows attackers to execute arbitrary code or cause denial of service....

Aug 22, 2023
CVE-2020-18494
8.8

CVE-2020-18494 is a buffer overflow vulnerability in HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by trick...

Aug 22, 2023
CVE-2020-18232
8.8

CVE-2020-18232 is a buffer overflow vulnerability in the HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by t...

Aug 22, 2023
CVE-2023-4362
8.8

This heap buffer overflow vulnerability in Google Chrome's Mojom IDL allows a remote attacker who has already compromised the renderer process to pote...

Aug 15, 2023
CVE-2023-4353
8.8

This vulnerability is a heap buffer overflow in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that allows remote attackers to...

Aug 15, 2023
CVE-2023-4355
8.8

This vulnerability allows remote attackers to exploit heap corruption in Chrome's V8 JavaScript engine through out-of-bounds memory access. Attackers ...

Aug 15, 2023
CVE-2023-40295
8.8

CVE-2023-40295 is a heap-based buffer overflow vulnerability in libboron's ur_strInitUtf8 function that allows attackers to execute arbitrary code or ...

Aug 14, 2023
CVE-2023-3732
8.8

This vulnerability allows out-of-bounds memory access in Chrome's Mojo IPC system, enabling a remote attacker who has compromised the renderer process...

Aug 1, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,747 CVEs classified as CWE-787, with 636 rated critical and 1,898 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free