CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,764
Total CVEs
643
Critical
1,908
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 323
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 166
6 Debian 145
7 Fedoraproject 100
8 Samsung 77
9 Siemens 74
10 Mozilla 62

All Out-of-bounds Write CVEs (2,764)

CVE-2020-18494
8.8

CVE-2020-18494 is a buffer overflow vulnerability in HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by trick...

Aug 22, 2023
CVE-2020-18232
8.8

CVE-2020-18232 is a buffer overflow vulnerability in the HDF5 library's H5S_close function that allows remote attackers to execute arbitrary code by t...

Aug 22, 2023
CVE-2023-4362
8.8

This heap buffer overflow vulnerability in Google Chrome's Mojom IDL allows a remote attacker who has already compromised the renderer process to pote...

Aug 15, 2023
CVE-2023-4353
8.8

This vulnerability is a heap buffer overflow in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome that allows remote attackers to...

Aug 15, 2023
CVE-2023-4355
8.8

This vulnerability allows remote attackers to exploit heap corruption in Chrome's V8 JavaScript engine through out-of-bounds memory access. Attackers ...

Aug 15, 2023
CVE-2023-40295
8.8

CVE-2023-40295 is a heap-based buffer overflow vulnerability in libboron's ur_strInitUtf8 function that allows attackers to execute arbitrary code or ...

Aug 14, 2023
CVE-2023-3732
8.8

This vulnerability allows out-of-bounds memory access in Chrome's Mojo IPC system, enabling a remote attacker who has compromised the renderer process...

Aug 1, 2023
CVE-2022-4914
8.8

This vulnerability is a heap buffer overflow in Chrome's PrintPreview feature that allows attackers to potentially exploit heap corruption. Attackers ...

Jul 29, 2023
CVE-2023-3598
8.8

This vulnerability allows a remote attacker to exploit heap corruption through out-of-bounds read/write in ANGLE (Almost Native Graphics Layer Engine)...

Jul 28, 2023
CVE-2023-2072
8.8

Rockwell Automation PowerMonitor 1000 has stored cross-site scripting vulnerabilities in publicly accessible web pages. Attackers can inject malicious...

Jul 11, 2023
CVE-2023-37211
8.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Jul 5, 2023
CVE-2023-35177
8.8

This vulnerability in HP LaserJet Pro printers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the compact font...

Jun 30, 2023
CVE-2023-36272
8.8

LibreDWG versions 0.10 through 0.12.5 contain a heap buffer overflow vulnerability in the bit_utf8_to_TU function. This allows attackers to execute ar...

Jun 23, 2023
CVE-2023-36274
8.8

CVE-2023-36274 is a heap buffer overflow vulnerability in LibreDWG's bit_write_TF function that allows attackers to execute arbitrary code or cause de...

Jun 23, 2023
CVE-2023-28176
8.8

CVE-2023-28176 is a memory safety vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird that could allow memory corruption. With sufficient e...

Jun 2, 2023
CVE-2023-25745
8.8

CVE-2023-25745 is a memory safety vulnerability in Firefox that could allow memory corruption and potentially arbitrary code execution. It affects Fir...

Jun 2, 2023
CVE-2023-23605
8.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Jun 2, 2023
CVE-2023-2929
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a malic...

May 30, 2023
CVE-2023-32981
8.8

This vulnerability in Jenkins Pipeline Utility Steps Plugin allows attackers who can provide crafted archive files as parameters to write arbitrary fi...

May 16, 2023
CVE-2022-47387
8.8

CVE-2022-47387 is a stack-based out-of-bounds write vulnerability in the CmpTraceMgr component of CODESYS industrial automation software. Authenticate...

May 15, 2023
CVE-2022-47389
8.8

This vulnerability allows authenticated remote attackers to exploit a stack-based out-of-bounds write in the CmpTraceMgr component of CODESYS products...

May 15, 2023
CVE-2022-47379
8.8

CVE-2022-47379 is an out-of-bounds write vulnerability in multiple CODESYS industrial automation products that allows authenticated remote attackers t...

May 15, 2023
CVE-2022-47381
8.8

This vulnerability allows authenticated remote attackers to exploit a stack-based out-of-bounds write in multiple CODESYS products, potentially leadin...

May 15, 2023
CVE-2022-47383
8.8

An authenticated remote attacker can exploit a stack-based out-of-bounds write vulnerability in the CmpTraceMgr component of CODESYS products to cause...

May 15, 2023
CVE-2022-47385
8.8

An authenticated remote attacker can exploit a stack-based out-of-bounds write vulnerability in the CmpAppForce component of CODESYS products to cause...

May 15, 2023
CVE-2023-2457
8.8

This vulnerability allows a remote attacker to trigger an out-of-bounds write in ChromeOS Audio Server by crafting a malicious audio file, potentially...

May 12, 2023
CVE-2023-31568
8.8

CVE-2023-31568 is a heap buffer overflow vulnerability in PoDoFo's RC4 encryption implementation that allows attackers to execute arbitrary code or ca...

May 10, 2023
CVE-2023-31976
8.8

CVE-2023-31976 is a stack buffer overflow vulnerability in libming v0.4.8's makeswf_preprocess function that allows attackers to execute arbitrary cod...

May 9, 2023
CVE-2022-32885
8.8

CVE-2022-32885 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious we...

May 8, 2023
CVE-2023-29578
8.8

CVE-2023-29578 is a heap buffer overflow vulnerability in mp4v2 library's MP4StringProperty destructor that allows attackers to execute arbitrary code...

Apr 24, 2023
CVE-2023-21085
8.8

This CVE describes a critical out-of-bounds write vulnerability in Android's NFC implementation that allows remote code execution without user interac...

Apr 19, 2023
CVE-2023-2133
8.8

This vulnerability allows remote attackers to exploit heap corruption in Google Chrome via a crafted HTML page. It affects Chrome users on any operati...

Apr 19, 2023
CVE-2021-45464
8.8

CVE-2021-45464 is an out-of-bounds write vulnerability in kvmtool's virtio balloon and PCI components that allows a guest OS user to execute arbitrary...

Apr 15, 2023
CVE-2023-29584
8.8

CVE-2023-29584 is a heap buffer overflow vulnerability in mp4v2 library's MP4GetVideoProfileLevel function. Attackers can exploit this to execute arbi...

Apr 14, 2023
CVE-2023-22613
8.8

This vulnerability allows attackers to write to arbitrary memory addresses in System Management Mode (SMM) by providing malformed pointers to SMI hand...

Apr 11, 2023
CVE-2023-22614
8.8

This vulnerability allows attackers to exploit insufficient input validation in BIOS Guard updates within InsydeH2O firmware, leading to memory corrup...

Apr 11, 2023
CVE-2023-29421
8.8

CVE-2023-29421 is an out-of-bounds write vulnerability in bzip3's libbzip3.a library that allows attackers to corrupt memory and potentially execute a...

Apr 6, 2023
CVE-2023-1810
8.8

This vulnerability is a heap buffer overflow in Google Chrome's Visuals component that allows a remote attacker who has already compromised the render...

Apr 4, 2023
CVE-2023-1812
8.8

This vulnerability allows a remote attacker to perform out-of-bounds memory access in Chrome's DOM Bindings by tricking a user into visiting a malicio...

Apr 4, 2023
CVE-2023-1820
8.8

A heap buffer overflow vulnerability in Google Chrome's browser history feature allows remote attackers to potentially exploit heap corruption. Attack...

Apr 4, 2023
CVE-2023-27042
8.8

CVE-2023-27042 is a buffer overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code or cause denial of servi...

Mar 24, 2023
CVE-2023-25267
8.8

This vulnerability allows authenticated attackers to trigger a stack-based buffer overflow in GFI Kerio Connect's webmail component by sending special...

Mar 15, 2023
CVE-2023-27103
8.8

CVE-2023-27103 is a heap buffer overflow vulnerability in Libde265 v1.0.11's derive_collocated_motion_vectors function that allows attackers to execut...

Mar 15, 2023
CVE-2023-1220
8.8

This vulnerability is a heap buffer overflow in Chrome's UMA (User Metrics Analysis) component that allows a remote attacker who has already compromis...

Mar 7, 2023
CVE-2023-1222
8.8

This vulnerability is a heap buffer overflow in Chrome's Web Audio API that allows remote attackers to potentially exploit heap corruption via malicio...

Mar 7, 2023
CVE-2023-0930
8.8

A heap buffer overflow vulnerability in Google Chrome's video processing component allows remote attackers to potentially execute arbitrary code or ca...

Feb 22, 2023
CVE-2023-24347
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-605L routers via a stack overflow in the webpage parameter. Attacke...

Feb 10, 2023
CVE-2023-24343
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the curTime ...

Feb 10, 2023
CVE-2023-24345
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the curTime ...

Feb 10, 2023
CVE-2023-0701
8.8

This vulnerability is a heap buffer overflow in Chrome's WebUI that allows remote attackers to potentially exploit heap corruption by convincing users...

Feb 7, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,764 CVEs classified as CWE-787, with 643 rated critical and 1,908 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free