CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,635
Total CVEs
600
Critical
1,822
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 297
2 Linux 228
3 Tenda 189
4 Adobe 186
5 Apple 161
6 Debian 134
7 Fedoraproject 91
8 Samsung 77
9 Siemens 67
10 Dlink 59

All Out-of-bounds Write CVEs (2,635)

CVE-2025-1016
9.8

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Feb 4, 2025
CVE-2025-1020
9.8

Memory safety vulnerabilities in Firefox and Thunderbird versions before 135 could allow attackers to execute arbitrary code through memory corruption...

Feb 4, 2025
CVE-2025-20634
9.8

This critical vulnerability in MediaTek modems allows remote code execution when a device connects to a malicious base station. Attackers can exploit ...

Feb 3, 2025
CVE-2024-12248
9.8

The Contec Health CMS8000 Patient Monitor has a critical vulnerability (CVE-2024-12248) that allows attackers to send specially crafted UDP packets to...

Jan 30, 2025
CVE-2024-12647
9.8

A buffer overflow vulnerability in CPCA font download processing for Canon multifunction printers allows network attackers to crash devices or execute...

Jan 28, 2025
CVE-2024-12649
9.8

A buffer overflow vulnerability in XPS data font processing allows attackers on the same network segment to crash affected Canon printers or execute a...

Jan 28, 2025
CVE-2024-57703
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers by exploiting a stack overflow in the setSchedWifi functio...

Jan 16, 2025
CVE-2024-57579
9.8

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote code execution. Attackers can exploit the limitSpeedUp para...

Jan 16, 2025
CVE-2024-57581
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the firewall configuratio...

Jan 16, 2025
CVE-2024-57575
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the WiFi configuration fu...

Jan 16, 2025
CVE-2024-48856
9.8

This critical vulnerability allows unauthenticated attackers to exploit an out-of-bounds write in QNX's PCX image codec, potentially leading to remote...

Jan 14, 2025
CVE-2025-0247
9.8

CVE-2025-0247 is a critical memory safety vulnerability in Firefox and Thunderbird that could allow attackers to execute arbitrary code through memory...

Jan 7, 2025
CVE-2024-20148
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected devices via Wi-Fi without user interaction. It affects MediaTek chips...

Jan 6, 2025
CVE-2024-53842
9.8

This critical vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. The out-of-bounds ...

Jan 3, 2025
CVE-2024-54534
9.8

This is a critical memory corruption vulnerability in Apple's WebKit browser engine that affects multiple Apple operating systems and Safari. Processi...

Dec 12, 2024
CVE-2024-47539
9.8

This CVE describes an out-of-bounds write vulnerability in GStreamer's MP4 demuxer that allows attackers to write up to 3 bytes beyond allocated memor...

Dec 12, 2024
CVE-2018-9430
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction by exploiting an out-of-boun...

Dec 2, 2024
CVE-2018-9418
9.8

CVE-2018-9418 is a critical stack buffer overflow vulnerability in Android's Bluetooth stack that allows remote code execution without user interactio...

Dec 2, 2024
CVE-2024-11236
9.8

This vulnerability allows attackers to cause an integer overflow in PHP's ldap_escape() function on 32-bit systems by providing long string inputs, le...

Nov 24, 2024
CVE-2024-8932
9.8

This vulnerability allows attackers to cause an integer overflow in PHP's ldap_escape() function on 32-bit systems by providing long string inputs, le...

Nov 22, 2024
CVE-2018-9478
9.8

CVE-2018-9478 is a critical Bluetooth SDP vulnerability in Android that allows remote code execution without user interaction. An attacker can exploit...

Nov 20, 2024
CVE-2024-49195
9.8

Mbed TLS versions 3.5.x through 3.6.x before 3.6.2 contain a buffer underrun vulnerability in the pkwrite function when writing opaque key pairs. This...

Oct 15, 2024
CVE-2024-32608
9.8

A memory corruption vulnerability in the HDF5 library's H5A__close function allows attackers to corrupt the instruction pointer, potentially leading t...

Oct 9, 2024
CVE-2024-20100
9.8

This critical vulnerability in MediaTek Wi-Fi drivers allows remote attackers to execute arbitrary code without authentication or user interaction. It...

Oct 7, 2024
CVE-2024-20103
9.8

This critical vulnerability in MediaTek wlan firmware allows remote attackers to execute arbitrary code without authentication or user interaction. It...

Oct 7, 2024
CVE-2024-41593
9.8

CVE-2024-41593 is a critical heap-based buffer overflow vulnerability in DrayTek Vigor310 devices that allows remote attackers to execute arbitrary co...

Oct 3, 2024
CVE-2024-46652
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers via a stack overflow in the fromAdvSetMacMtuWan function. ...

Sep 20, 2024
CVE-2024-31570
9.8

CVE-2024-31570 is a critical stack-based buffer overflow vulnerability in libfreeimage's XPM file parser. Attackers can exploit this by crafting malic...

Sep 19, 2024
CVE-2024-46046
9.8

CVE-2024-46046 is a critical stack overflow vulnerability in Tenda FH451 routers that allows remote code execution. Attackers can exploit this by send...

Sep 13, 2024
CVE-2024-46044
9.8

CVE-2024-46044 is a critical stack overflow vulnerability in Tenda CH22 routers that allows remote attackers to execute arbitrary code by sending spec...

Sep 13, 2024
CVE-2024-8389
9.8

CVE-2024-8389 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulne...

Sep 3, 2024
CVE-2024-8384
9.8

A critical memory corruption vulnerability in Mozilla's JavaScript garbage collector could allow attackers to execute arbitrary code or cause denial o...

Sep 3, 2024
CVE-2024-8387
9.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Sep 3, 2024
CVE-2024-45508
9.8

CVE-2024-45508 is a critical out-of-bounds write vulnerability in HTMLDOC's PDF/PS parsing functionality. Attackers can exploit this to execute arbitr...

Sep 1, 2024
CVE-2024-44556
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the setIptvInfo function. Attacke...

Aug 26, 2024
CVE-2024-44563
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1806 routers via a stack overflow in the setIptvInfo function. Attacke...

Aug 26, 2024
CVE-2024-42815
9.8

A buffer overflow vulnerability in TP-Link RE365 V1 routers allows attackers to crash devices or execute arbitrary commands by sending specially craft...

Aug 19, 2024
CVE-2024-42394
9.8

This vulnerability in the Soft AP Daemon Service allows unauthenticated remote attackers to execute arbitrary commands on affected systems, leading to...

Aug 6, 2024
CVE-2024-41459
9.8

CVE-2024-41459 is a critical stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code ...

Jul 24, 2024
CVE-2024-41461
9.8

CVE-2024-41461 is a critical stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code ...

Jul 24, 2024
CVE-2024-40129
9.8

CVE-2024-40129 is a critical buffer overflow vulnerability in Open5GS v2.6.4's PFCP context handling that allows remote attackers to execute arbitrary...

Jul 16, 2024
CVE-2024-33182
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC18 routers. Attackers can exploit this by sending specially crafted...

Jul 16, 2024
CVE-2024-40415
9.8

A stack-based buffer overflow vulnerability in Tenda AX1806 router firmware allows remote attackers to execute arbitrary code or cause denial of servi...

Jul 15, 2024
CVE-2024-40414
9.8

A stack-based buffer overflow vulnerability in Tenda AX1806 router firmware allows remote attackers to execute arbitrary code or crash the device. Thi...

Jul 15, 2024
CVE-2023-48194
9.8

This vulnerability in Tenda AC8v4 routers allows remote code execution due to a buffer overflow in the set_client_qos function. Attackers can exploit ...

Jul 9, 2024
CVE-2024-37079
9.8

CVE-2024-37079 is a critical heap overflow vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. Attacke...

Jun 18, 2024
CVE-2024-38439
9.8

CVE-2024-38439 is a critical heap-based buffer overflow vulnerability in Netatalk's PAM authentication module. An attacker can exploit this to execute...

Jun 16, 2024
CVE-2024-37036
9.8

CVE-2024-37036 is an out-of-bounds write vulnerability in Schneider Electric products that allows authentication bypass when attackers send malformed ...

Jun 12, 2024
CVE-2024-36761
9.8

CVE-2024-36761 is a critical stack overflow vulnerability in naga v0.14.0's WGSL parser that allows attackers to execute arbitrary code or cause denia...

Jun 12, 2024
CVE-2024-32615
9.8

CVE-2024-32615 is a critical heap-based buffer overflow vulnerability in the HDF5 library's n-bit decompression function. Attackers can exploit this t...

May 14, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,635 CVEs classified as CWE-787, with 600 rated critical and 1,822 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free