CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,778
Total CVEs
652
Critical
1,913
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 332
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 166
6 Debian 147
7 Fedoraproject 101
8 Samsung 77
9 Siemens 74
10 Mozilla 62

All Out-of-bounds Write CVEs (2,778)

CVE-2023-25267
8.8

This vulnerability allows authenticated attackers to trigger a stack-based buffer overflow in GFI Kerio Connect's webmail component by sending special...

Mar 15, 2023
CVE-2023-27103
8.8

CVE-2023-27103 is a heap buffer overflow vulnerability in Libde265 v1.0.11's derive_collocated_motion_vectors function that allows attackers to execut...

Mar 15, 2023
CVE-2023-1220
8.8

This vulnerability is a heap buffer overflow in Chrome's UMA (User Metrics Analysis) component that allows a remote attacker who has already compromis...

Mar 7, 2023
CVE-2023-1222
8.8

This vulnerability is a heap buffer overflow in Chrome's Web Audio API that allows remote attackers to potentially exploit heap corruption via malicio...

Mar 7, 2023
CVE-2023-0930
8.8

A heap buffer overflow vulnerability in Google Chrome's video processing component allows remote attackers to potentially execute arbitrary code or ca...

Feb 22, 2023
CVE-2023-24347
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-605L routers via a stack overflow in the webpage parameter. Attacke...

Feb 10, 2023
CVE-2023-24343
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the curTime ...

Feb 10, 2023
CVE-2023-24345
8.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the curTime ...

Feb 10, 2023
CVE-2023-0701
8.8

This vulnerability is a heap buffer overflow in Chrome's WebUI that allows remote attackers to potentially exploit heap corruption by convincing users...

Feb 7, 2023
CVE-2022-2415
8.8

This vulnerability is a heap buffer overflow in Chrome's WebGL implementation that allows a remote attacker to potentially exploit heap corruption via...

Jul 28, 2022
CVE-2022-1876
8.8

A heap buffer overflow vulnerability in Chrome DevTools allows attackers to potentially exploit heap corruption. This affects users who install malici...

Jul 27, 2022
CVE-2022-1638
8.8

This vulnerability is a heap buffer overflow in Chrome's V8 Internationalization component that allows remote attackers to potentially exploit heap co...

Jul 26, 2022
CVE-2022-1483
8.8

This vulnerability is a heap buffer overflow in Chrome's WebGPU implementation that allows a remote attacker who has already compromised the renderer ...

Jul 26, 2022
CVE-2022-1489
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's UI Shelf component on Chrome OS and Lacros, potentially...

Jul 26, 2022
CVE-2022-1143
8.8

A heap buffer overflow vulnerability in Chrome's WebUI DevTools allows remote attackers to potentially exploit heap corruption by convincing users to ...

Jul 23, 2022
CVE-2022-22026
8.8

CVE-2022-22026 is a privilege escalation vulnerability in Windows Client Server Run-time Subsystem (CSRSS) that allows authenticated attackers to gain...

Jul 12, 2022
CVE-2022-21767
8.8

CVE-2022-21767 is a Bluetooth stack vulnerability in MediaTek chipsets that allows local privilege escalation without user interaction. An attacker ca...

Jul 6, 2022
CVE-2021-42585
8.8

CVE-2021-42585 is a heap buffer overflow vulnerability in LibreDWG's dwgread library that allows remote code execution when processing malicious DWG f...

May 23, 2022
CVE-2022-23973
8.8

This vulnerability allows unauthenticated attackers on the local network to execute arbitrary code on ASUS RT-AX56U routers by exploiting a stack-base...

Apr 7, 2022
CVE-2022-25596
8.8

This vulnerability in ASUS RT-AC56U routers allows unauthenticated attackers on the local network to execute arbitrary code by exploiting a heap buffe...

Apr 7, 2022
CVE-2022-0470
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to heap corru...

Apr 5, 2022
CVE-2022-0797
8.8

This vulnerability allows remote attackers to perform out-of-bounds memory writes in Google Chrome's Mojo IPC framework via a crafted HTML page. Attac...

Apr 5, 2022
CVE-2022-0454
8.8

A heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome allows remote attackers to potentially exploit he...

Apr 5, 2022
CVE-2022-0604
8.8

This vulnerability allows an attacker to exploit heap corruption in Google Chrome's Tab Groups feature through a malicious extension and crafted HTML ...

Apr 5, 2022
CVE-2022-0610
8.8

This vulnerability in Google Chrome's Gamepad API implementation allows remote attackers to potentially exploit heap corruption via a crafted HTML pag...

Apr 5, 2022
CVE-2021-33657
8.8

CVE-2021-33657 is a heap buffer overflow vulnerability in SDL's BMP image parsing code. Attackers can exploit this by crafting malicious BMP files to ...

Apr 1, 2022
CVE-2022-25023
8.8

CVE-2022-25023 is a heap-buffer overflow vulnerability in the AudioFile library's fouBytesToInt() function. Attackers can exploit this to execute arbi...

Feb 28, 2022
CVE-2022-25293
8.8

CVE-2022-25293 is a stack-based buffer overflow vulnerability in systemd on WatchGuard Firebox and XTM appliances, allowing authenticated remote attac...

Feb 24, 2022
CVE-2022-24369
8.8

This is a critical remote code execution vulnerability in Foxit PDF Reader that allows attackers to execute arbitrary code by tricking users into open...

Feb 18, 2022
CVE-2022-24361
8.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Feb 18, 2022
CVE-2022-0306
8.8

This vulnerability is a heap buffer overflow in PDFium, Chrome's PDF rendering engine, that allows remote attackers to potentially exploit heap corrup...

Feb 12, 2022
CVE-2022-0310
8.8

A heap buffer overflow vulnerability in Chrome's Task Manager allows remote attackers to potentially exploit heap corruption through specific user int...

Feb 12, 2022
CVE-2022-0101
8.8

A heap buffer overflow vulnerability in Google Chrome's bookmarks feature allows remote attackers to potentially exploit heap corruption by convincing...

Feb 12, 2022
CVE-2022-23566
8.8

CVE-2022-23566 is a heap out-of-bounds write vulnerability in TensorFlow's Grappler component that allows attackers to write arbitrary data to memory....

Feb 4, 2022
CVE-2021-40002
8.8

This CVE describes an out-of-bounds write vulnerability in Bluetooth modules that could allow remote attackers to execute arbitrary commands on affect...

Jan 10, 2022
CVE-2021-4055
8.8

This vulnerability is a heap buffer overflow in Google Chrome extensions that allows an attacker to potentially exploit heap corruption. It affects us...

Dec 23, 2021
CVE-2021-0967
8.8

This vulnerability allows an attacker to write data beyond allocated memory bounds in Android's Vorbis audio codec library. It could lead to remote in...

Dec 15, 2021
CVE-2021-0918
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android 12 ...

Dec 15, 2021
CVE-2021-43071
8.8

This vulnerability allows remote attackers to execute arbitrary code on Fortinet FortiWeb web application firewalls via specially crafted HTTP request...

Dec 9, 2021
CVE-2021-36194
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on FortiWeb web application firewalls through stack-based buffer overflows...

Dec 9, 2021
CVE-2021-43534
8.8

This CVE describes memory safety bugs in Mozilla products that could lead to memory corruption. With sufficient effort, attackers could potentially ex...

Dec 8, 2021
CVE-2021-41017
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary code or commands on affected FortiWeb devices via crafted HTTP requests....

Dec 8, 2021
CVE-2020-36129
8.8

CVE-2020-36129 is a stack buffer overflow vulnerability in AOM (AOMedia Video 1) codec library version 2.0.1 that allows attackers to execute arbitrar...

Dec 2, 2021
CVE-2020-36131
8.8

CVE-2020-36131 is a stack buffer overflow vulnerability in AOM (AOMedia Video 1) codec library version 2.0.1, specifically in the stats/rate_hist.c co...

Dec 2, 2021
CVE-2019-8922
8.8

This heap-based buffer overflow vulnerability in BlueZ's bluetoothd service allows attackers to execute arbitrary code or cause denial of service by s...

Nov 29, 2021
CVE-2021-38493
8.8

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Nov 3, 2021
CVE-2021-38495
8.8

This CVE describes memory safety bugs in Mozilla Thunderbird and Firefox ESR that could lead to memory corruption. With sufficient effort, attackers c...

Nov 3, 2021
CVE-2021-37979
8.8

This vulnerability is a heap buffer overflow in WebRTC in Google Chrome that allows remote attackers to potentially exploit heap corruption. Attackers...

Nov 2, 2021
CVE-2021-30632
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a malic...

Oct 8, 2021
CVE-2021-39531
8.8

CVE-2021-39531 is a stack-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause...

Sep 20, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,778 CVEs classified as CWE-787, with 652 rated critical and 1,913 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free