CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,933
Total CVEs
716
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 362
2 Linux 228
3 Adobe 213
4 Apple 194
5 Tenda 189
6 Debian 163
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,933)

CVE-2019-1140
8.8

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by tricking...

Aug 14, 2019
CVE-2019-1149
8.8

This CVE describes a remote code execution vulnerability in Windows font library that allows attackers to execute arbitrary code by tricking users int...

Aug 14, 2019
CVE-2019-1151
8.8

This is a remote code execution vulnerability in Windows font library that allows attackers to execute arbitrary code by tricking users into viewing m...

Aug 14, 2019
CVE-2025-68473
8.6

This vulnerability is an out-of-bounds write in the ESP-IDF Bluetooth host stack that occurs when more than 32 services are discovered during Bluetoot...

Dec 27, 2025
CVE-2025-23107
8.6

This vulnerability in Samsung Exynos 1480 and 2400 mobile processors allows attackers to write data beyond allocated memory boundaries due to missing ...

Jun 3, 2025
CVE-2025-23103
8.6

A memory corruption vulnerability in Samsung Exynos 1480 and 2400 mobile processors allows attackers to write data beyond allocated buffer boundaries....

Jun 3, 2025
CVE-2025-20182
8.6

An unauthenticated remote attacker can cause affected Cisco network devices to crash and reload by sending specially crafted IKEv2 protocol messages. ...

May 7, 2025
CVE-2024-20501
8.6

This vulnerability allows unauthenticated remote attackers to cause denial of service on Cisco Meraki MX and Z Series devices by sending crafted HTTPS...

Oct 2, 2024
CVE-2024-20375
8.6

An unauthenticated remote attacker can send a specially crafted SIP message to Cisco Unified Communications Manager systems, causing them to reload an...

Aug 21, 2024
CVE-2023-7272
8.6

This vulnerability in Eclipse Parsson allows attackers to cause denial of service by sending JSON documents with deeply nested objects, triggering Jav...

Jul 17, 2024
CVE-2024-20308
8.6

A heap underflow vulnerability in Cisco IOS/IOS XE IKEv1 fragmentation handling allows unauthenticated remote attackers to trigger device reloads via ...

Mar 27, 2024
CVE-2023-26496
8.6

This vulnerability allows memory corruption in Samsung baseband chipsets due to improper parameter length checking while parsing SDP fmtp attributes. ...

Mar 23, 2023
CVE-2023-26497
8.6

This vulnerability in Samsung baseband chipsets allows memory corruption when processing Session Description Negotiation for Video Configuration Attri...

Mar 21, 2023
CVE-2021-21280
8.6

This vulnerability allows attackers to cause an out-of-bounds write in Contiki-NG IoT operating system when processing 6LoWPAN packets with extension ...

Jun 18, 2021
CVE-2022-28182
8.5

This vulnerability in NVIDIA GPU Display Driver for Windows allows attackers to execute arbitrary code through specially crafted shaders, potentially ...

May 17, 2022
CVE-2026-24926
8.4

This CVE describes an out-of-bounds write vulnerability in Huawei camera modules that could allow attackers to crash affected systems. The vulnerabili...

Feb 6, 2026
CVE-2021-47775
8.4

CVE-2021-47775 is a buffer overflow vulnerability in YouTube Video Grabber (YouTube Downloader) that allows attackers to execute arbitrary code by ove...

Jan 15, 2026
CVE-2025-20979
8.4

CVE-2025-20979 is an out-of-bounds write vulnerability in libsavscmn library affecting Android devices prior to version 15. This allows local attacker...

May 7, 2025
CVE-2024-45555
8.4

This vulnerability allows attackers to bypass boot verification by overwriting an already verified IFS2 image, enabling injection of unauthorized prog...

Jan 6, 2025
CVE-2024-38665
8.4

This vulnerability allows an authenticated user to perform an out-of-bounds write in Intel Graphics Drivers, potentially enabling privilege escalation...

Nov 13, 2024
CVE-2024-20104
8.4

This vulnerability in MediaTek's da component allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated privile...

Nov 4, 2024
CVE-2024-39816
8.4

This vulnerability allows a local attacker to execute arbitrary code in pre-installed apps on OpenHarmony devices through an out-of-bounds write. It a...

Sep 2, 2024
CVE-2024-38386
8.4

This vulnerability allows a local attacker to execute arbitrary code in pre-installed applications on OpenHarmony devices through an out-of-bounds wri...

Sep 2, 2024
CVE-2024-31956
8.4

This vulnerability in Samsung Exynos processors allows attackers to write data beyond allocated memory boundaries due to insufficient buffer length ch...

Jun 13, 2024
CVE-2023-52755
8.4

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to write beyond allocated memory boundaries in the smb_inherit_dacl() funct...

May 21, 2024
CVE-2024-29746
8.4

CVE-2024-29746 is an out-of-bounds write vulnerability in the lpm_req_handler function of lpm.c in Android's kernel. This allows local attackers to es...

Apr 5, 2024
CVE-2024-20844
8.4

This is an out-of-bounds write vulnerability in Samsung's libsavsac.so library that allows a local attacker to execute arbitrary code with elevated pr...

Apr 2, 2024
CVE-2024-20053
8.4

This vulnerability in MediaTek's flashc component allows an attacker with system privileges to perform an out-of-bounds write due to an uncaught excep...

Apr 1, 2024
CVE-2024-27219
8.4

This vulnerability allows local privilege escalation on affected Android Pixel devices through an out-of-bounds write in the tmu_set_pi function. Atta...

Mar 11, 2024
CVE-2024-27226
8.4

This vulnerability allows local privilege escalation on affected Android Pixel devices through an out-of-bounds write in the tmu_config_gov_params fun...

Mar 11, 2024
CVE-2024-22005
8.4

CVE-2024-22005 is an authentication bypass vulnerability in Android Pixel devices due to improper cryptographic implementation. This allows local atta...

Mar 11, 2024
CVE-2024-27204
8.4

CVE-2024-27204 is an out-of-bounds write vulnerability in the tmu_set_gov_active function of tmu.c in Android's Pixel kernel. This allows local attack...

Mar 11, 2024
CVE-2024-20029
8.4

This CVE describes an out-of-bounds write vulnerability in MediaTek wlan firmware due to improper input validation. It allows local attackers to escal...

Mar 4, 2024
CVE-2024-20812
8.4

This vulnerability is an out-of-bounds write in the padmd_vld_htbl function of libpadm.so on Samsung devices, allowing a local attacker to execute arb...

Feb 6, 2024
CVE-2023-42535
8.4

This vulnerability allows a local attacker to write data beyond allocated memory boundaries in the read_block function of vold (Android volume daemon)...

Nov 7, 2023
CVE-2022-21804
8.4

This vulnerability is an out-of-bounds write in Intel's QAT Driver for Windows that allows authenticated users to potentially escalate privileges via ...

May 10, 2023
CVE-2022-22084
8.4

This vulnerability allows memory corruption when processing QCP audio files due to insufficient length validation in Qualcomm Snapdragon chipsets. Att...

Jun 14, 2022
CVE-2021-30288
8.4

This vulnerability allows attackers to trigger a stack overflow by exploiting improper length validation of TLV (Type-Length-Value) data structures in...

Oct 20, 2021
CVE-2021-30292
8.4

This vulnerability allows memory corruption due to improper validation of client data during memory allocation in Qualcomm Snapdragon chipsets. Attack...

Oct 20, 2021
CVE-2021-29075
8.4

This CVE describes a stack-based buffer overflow vulnerability in certain NETGEAR WiFi systems that allows an authenticated attacker to execute arbitr...

Mar 23, 2021
CVE-2024-39431
8.3

This vulnerability in UMTS RLC driver allows remote attackers to write data beyond allocated memory boundaries due to missing bounds checks. It affect...

Sep 27, 2024
CVE-2021-45637
8.3

This vulnerability allows unauthenticated attackers to trigger a stack-based buffer overflow on affected NETGEAR routers. Successful exploitation coul...

Dec 26, 2021
CVE-2021-45573
8.3

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers to execu...

Dec 26, 2021
CVE-2021-22555
8.3

This vulnerability allows an attacker to perform heap out-of-bounds writes in the Linux kernel's netfilter subsystem, specifically in x_tables.c. Atta...

Jul 7, 2021
CVE-2025-10451
8.2

This vulnerability involves an unchecked output buffer in System Management Mode (SMM) that could allow arbitrary code execution and memory corruption...

Dec 12, 2025
CVE-2025-65001
8.2

This vulnerability in Fujitsu fbiosdrv.sys driver allows attackers to write beyond allocated memory boundaries, potentially leading to privilege escal...

Nov 12, 2025
CVE-2025-35971
8.2

An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows unprivileged local attackers to cause denial of service...

Nov 11, 2025
CVE-2025-30255
8.2

An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows unprivileged attackers to cause denial of service. The ...

Nov 11, 2025
CVE-2025-4421
8.2

This is a critical memory corruption vulnerability (CWE-787) affecting Lenovo systems, allowing attackers to execute arbitrary code or cause system cr...

Jul 30, 2025
CVE-2024-39927
8.2

This CVE describes an out-of-bounds write vulnerability in Ricoh MFPs and printers that allows remote attackers to send specially crafted requests. Ex...

Jul 10, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,933 CVEs classified as CWE-787, with 716 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free