CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,747)
This vulnerability is an out-of-bounds write in Chrome's Streams API that allows remote attackers to execute arbitrary code within the browser's sandb...
May 30, 2024This vulnerability allows an attacker to execute arbitrary code or cause a denial of service by providing a malicious .msh file to libigl. It affects ...
May 28, 2024This vulnerability allows an attacker to execute arbitrary code or cause a denial of service by providing a malicious .msh file to libigl's readMSH fu...
May 28, 2024This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code by tricking users...
May 14, 2024This is a critical remote code execution vulnerability in NETGEAR R7800 routers that allows network-adjacent attackers to execute arbitrary code as ro...
May 7, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite. Att...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro by tricking user...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro by tricking user...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K image files in Sante DICOM Viewer Pr...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Sante DICOM Viewer Pro. Attackers can e...
May 3, 2024This CVE describes an out-of-bounds write vulnerability in Keyence KV STUDIO, KV REPLAY VIEWER, and VT5-WX15/WX12 industrial software. Attackers can e...
Apr 15, 2024This CVE describes a critical out-of-bounds write vulnerability in MediaTek modem protocol that allows remote code execution without user interaction ...
Apr 1, 2024This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Mar 19, 2024This is a memory corruption vulnerability (CWE-787) in Apple's web content processing components that could allow arbitrary code execution when proces...
Mar 8, 2024This vulnerability allows a remote attacker to perform out-of-bounds memory access in Chrome's V8 JavaScript engine via a crafted HTML page. This coul...
Mar 6, 2024This vulnerability allows remote attackers to perform out-of-bounds memory access in Chrome's Blink rendering engine by tricking users into visiting a...
Feb 21, 2024CVE-2022-23092 is a memory corruption vulnerability in lib9p's RWALK message handling that allows a malicious bhyve guest kernel to overwrite host mem...
Feb 15, 2024CVE-2022-23087 is a memory corruption vulnerability in the e1000 network adapter emulation in bhyve hypervisor. A malicious guest VM can overwrite hos...
Feb 15, 2024A heap buffer overflow vulnerability in imlib2's image parsing function allows attackers to execute arbitrary code or crash applications by processing...
Feb 9, 2024A stack buffer overflow vulnerability in Firefox's WebAudio OscillatorNode could allow attackers to cause a crash or potentially execute arbitrary cod...
Jan 23, 2024This CVE describes memory corruption vulnerabilities in Apple's WebKit browser engine that could allow arbitrary code execution when processing malici...
Jan 23, 2024This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption via ...
Jan 16, 2024This vulnerability allows a remote attacker to exploit heap corruption in Google Chrome's V8 JavaScript engine via a crafted HTML page. Attackers coul...
Jan 16, 2024This vulnerability is a heap buffer overflow in WebRTC within Google Chrome that allows remote attackers to potentially exploit heap corruption via a ...
Dec 21, 2023CVE-2023-6873 is a memory corruption vulnerability in Firefox that could allow an attacker to execute arbitrary code on a victim's system. It affects ...
Dec 19, 2023This CVE describes a heap buffer overflow vulnerability in Firefox's WebGL DrawElementsInstanced method when used with Mesa VM driver. An attacker cou...
Dec 19, 2023CVE-2023-6858 is a heap buffer overflow vulnerability in Firefox's nsTextFragment component caused by insufficient out-of-memory handling. Attackers c...
Dec 19, 2023This vulnerability allows remote attackers to execute arbitrary code via a heap buffer overflow in Firefox's nsWindow::PickerOpen method when running ...
Dec 19, 2023This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....
Nov 30, 2023A buffer overflow vulnerability in zlib-ng's minizip-ng library allows attackers to execute arbitrary code by providing a specially crafted file to th...
Nov 22, 2023This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Nov 21, 2023This is an authenticated buffer overflow vulnerability in RedisGraph that allows remote code execution. Attackers with valid authentication can exploi...
Nov 6, 2023CVE-2023-44398 is an out-of-bounds write vulnerability in Exiv2 v0.28.0 that allows remote code execution when processing a malicious image file. Atta...
Nov 6, 2023CVE-2023-46602 is a stack-based buffer overflow vulnerability in the icFixXml function of International Color Consortium's DemoIccMAX library. This al...
Oct 23, 2023A heap buffer overflow vulnerability in Chrome's PDF renderer allows remote attackers to potentially exploit heap corruption via a crafted PDF file. U...
Oct 11, 2023CVE-2023-43641 is a critical out-of-bounds array access vulnerability in libcue that allows remote code execution. Attackers can exploit this by trick...
Oct 9, 2023This vulnerability allows a paired Bluetooth device to execute arbitrary code on an Android device without user interaction. It affects Android device...
Sep 11, 2023This CVE describes a buffer overflow vulnerability in D-Link DIR-605L routers that allows authenticated attackers to execute arbitrary code by sending...
Sep 11, 2023CVE-2023-4584 is a memory corruption vulnerability in Mozilla products that could allow attackers to execute arbitrary code on affected systems. This ...
Sep 11, 2023A buffer overflow vulnerability in VirusTotal YARA v4.3.2 allows remote attackers to execute arbitrary code via the yr_execute_cod function in the exe...
Aug 28, 2023A heap overflow vulnerability in FreeImage 1.18.0 allows attackers to execute arbitrary code or cause denial of service by processing specially crafte...
Aug 22, 2023CVE-2021-40265 is a heap overflow vulnerability in FreeImage's JPEG plugin that allows attackers to execute arbitrary code or cause denial of service....
Aug 22, 2023CVE-2020-18494 is a buffer overflow vulnerability in HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by trick...
Aug 22, 2023CVE-2020-18232 is a buffer overflow vulnerability in the HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by t...
Aug 22, 2023This heap buffer overflow vulnerability in Google Chrome's Mojom IDL allows a remote attacker who has already compromised the renderer process to pote...
Aug 15, 2023This vulnerability is a heap buffer overflow in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that allows remote attackers to...
Aug 15, 2023This vulnerability allows remote attackers to exploit heap corruption in Chrome's V8 JavaScript engine through out-of-bounds memory access. Attackers ...
Aug 15, 2023CVE-2023-40295 is a heap-based buffer overflow vulnerability in libboron's ur_strInitUtf8 function that allows attackers to execute arbitrary code or ...
Aug 14, 2023This vulnerability allows out-of-bounds memory access in Chrome's Mojo IPC system, enabling a remote attacker who has compromised the renderer process...
Aug 1, 2023About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,747 CVEs classified as CWE-787, with 636 rated critical and 1,898 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free