CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,635)
This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...
Feb 4, 2025Memory safety vulnerabilities in Firefox and Thunderbird versions before 135 could allow attackers to execute arbitrary code through memory corruption...
Feb 4, 2025This critical vulnerability in MediaTek modems allows remote code execution when a device connects to a malicious base station. Attackers can exploit ...
Feb 3, 2025The Contec Health CMS8000 Patient Monitor has a critical vulnerability (CVE-2024-12248) that allows attackers to send specially crafted UDP packets to...
Jan 30, 2025A buffer overflow vulnerability in CPCA font download processing for Canon multifunction printers allows network attackers to crash devices or execute...
Jan 28, 2025A buffer overflow vulnerability in XPS data font processing allows attackers on the same network segment to crash affected Canon printers or execute a...
Jan 28, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers by exploiting a stack overflow in the setSchedWifi functio...
Jan 16, 2025This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote code execution. Attackers can exploit the limitSpeedUp para...
Jan 16, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the firewall configuratio...
Jan 16, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the WiFi configuration fu...
Jan 16, 2025This critical vulnerability allows unauthenticated attackers to exploit an out-of-bounds write in QNX's PCX image codec, potentially leading to remote...
Jan 14, 2025CVE-2025-0247 is a critical memory safety vulnerability in Firefox and Thunderbird that could allow attackers to execute arbitrary code through memory...
Jan 7, 2025This vulnerability allows remote attackers to execute arbitrary code on affected devices via Wi-Fi without user interaction. It affects MediaTek chips...
Jan 6, 2025This critical vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. The out-of-bounds ...
Jan 3, 2025This is a critical memory corruption vulnerability in Apple's WebKit browser engine that affects multiple Apple operating systems and Safari. Processi...
Dec 12, 2024This CVE describes an out-of-bounds write vulnerability in GStreamer's MP4 demuxer that allows attackers to write up to 3 bytes beyond allocated memor...
Dec 12, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction by exploiting an out-of-boun...
Dec 2, 2024CVE-2018-9418 is a critical stack buffer overflow vulnerability in Android's Bluetooth stack that allows remote code execution without user interactio...
Dec 2, 2024This vulnerability allows attackers to cause an integer overflow in PHP's ldap_escape() function on 32-bit systems by providing long string inputs, le...
Nov 24, 2024This vulnerability allows attackers to cause an integer overflow in PHP's ldap_escape() function on 32-bit systems by providing long string inputs, le...
Nov 22, 2024CVE-2018-9478 is a critical Bluetooth SDP vulnerability in Android that allows remote code execution without user interaction. An attacker can exploit...
Nov 20, 2024Mbed TLS versions 3.5.x through 3.6.x before 3.6.2 contain a buffer underrun vulnerability in the pkwrite function when writing opaque key pairs. This...
Oct 15, 2024A memory corruption vulnerability in the HDF5 library's H5A__close function allows attackers to corrupt the instruction pointer, potentially leading t...
Oct 9, 2024This critical vulnerability in MediaTek Wi-Fi drivers allows remote attackers to execute arbitrary code without authentication or user interaction. It...
Oct 7, 2024This critical vulnerability in MediaTek wlan firmware allows remote attackers to execute arbitrary code without authentication or user interaction. It...
Oct 7, 2024CVE-2024-41593 is a critical heap-based buffer overflow vulnerability in DrayTek Vigor310 devices that allows remote attackers to execute arbitrary co...
Oct 3, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers via a stack overflow in the fromAdvSetMacMtuWan function. ...
Sep 20, 2024CVE-2024-31570 is a critical stack-based buffer overflow vulnerability in libfreeimage's XPM file parser. Attackers can exploit this by crafting malic...
Sep 19, 2024CVE-2024-46046 is a critical stack overflow vulnerability in Tenda FH451 routers that allows remote code execution. Attackers can exploit this by send...
Sep 13, 2024CVE-2024-46044 is a critical stack overflow vulnerability in Tenda CH22 routers that allows remote attackers to execute arbitrary code by sending spec...
Sep 13, 2024CVE-2024-8389 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulne...
Sep 3, 2024A critical memory corruption vulnerability in Mozilla's JavaScript garbage collector could allow attackers to execute arbitrary code or cause denial o...
Sep 3, 2024This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Sep 3, 2024CVE-2024-45508 is a critical out-of-bounds write vulnerability in HTMLDOC's PDF/PS parsing functionality. Attackers can exploit this to execute arbitr...
Sep 1, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the setIptvInfo function. Attacke...
Aug 26, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the setIptvInfo function. Attacke...
Aug 26, 2024A buffer overflow vulnerability in TP-Link RE365 V1 routers allows attackers to crash devices or execute arbitrary commands by sending specially craft...
Aug 19, 2024This vulnerability in the Soft AP Daemon Service allows unauthenticated remote attackers to execute arbitrary commands on affected systems, leading to...
Aug 6, 2024CVE-2024-41459 is a critical stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code ...
Jul 24, 2024CVE-2024-41461 is a critical stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code ...
Jul 24, 2024CVE-2024-40129 is a critical buffer overflow vulnerability in Open5GS v2.6.4's PFCP context handling that allows remote attackers to execute arbitrary...
Jul 16, 2024This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC18 routers. Attackers can exploit this by sending specially crafted...
Jul 16, 2024A stack-based buffer overflow vulnerability in Tenda AX1806 router firmware allows remote attackers to execute arbitrary code or cause denial of servi...
Jul 15, 2024A stack-based buffer overflow vulnerability in Tenda AX1806 router firmware allows remote attackers to execute arbitrary code or crash the device. Thi...
Jul 15, 2024This vulnerability in Tenda AC8v4 routers allows remote code execution due to a buffer overflow in the set_client_qos function. Attackers can exploit ...
Jul 9, 2024CVE-2024-37079 is a critical heap overflow vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. Attacke...
Jun 18, 2024CVE-2024-38439 is a critical heap-based buffer overflow vulnerability in Netatalk's PAM authentication module. An attacker can exploit this to execute...
Jun 16, 2024CVE-2024-37036 is an out-of-bounds write vulnerability in Schneider Electric products that allows authentication bypass when attackers send malformed ...
Jun 12, 2024CVE-2024-36761 is a critical stack overflow vulnerability in naga v0.14.0's WGSL parser that allows attackers to execute arbitrary code or cause denia...
Jun 12, 2024CVE-2024-32615 is a critical heap-based buffer overflow vulnerability in the HDF5 library's n-bit decompression function. Attackers can exploit this t...
May 14, 2024About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,635 CVEs classified as CWE-787, with 600 rated critical and 1,822 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free