CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,934)
This CVE describes an out-of-bounds write vulnerability in Ricoh MFPs and printers that allows remote attackers to send specially crafted requests. Ex...
Jul 10, 2024This vulnerability allows remote attackers to execute arbitrary code in pre-installed applications on OpenHarmony devices through an out-of-bounds wri...
Jul 2, 2024This CVE describes an out-of-bounds write vulnerability in AutomationDirect P3-550E programming software that allows remote attackers to cause heap-ba...
May 28, 2024A heap-based buffer overflow vulnerability in AutomationDirect P3-550E programming software allows unauthenticated attackers to send specially crafted...
May 28, 2024This vulnerability allows remote attackers to write arbitrary null bytes to heap memory in AutomationDirect P3-550E PLC programming software. Exploita...
May 28, 2024CVE-2022-23085 is an integer overflow vulnerability in FreeBSD's netmap subsystem that allows kernel memory corruption. A privileged process within a ...
Feb 15, 2024This vulnerability allows local attackers to execute arbitrary code on affected Samsung devices by exploiting an out-of-bounds write in the mPOS TUI t...
May 4, 2023This vulnerability allows attackers to execute arbitrary code on the host system by exploiting a stack-based buffer overflow in VMware's Bluetooth sha...
Apr 25, 2023A buffer overflow vulnerability in Bestechnic Bluetooth Mesh SDK allows attackers to execute arbitrary code during device provisioning by sending spec...
Feb 1, 2023CVE-2022-31364 is a buffer overflow vulnerability in Cypress Bluetooth Mesh SDK that allows remote attackers to execute arbitrary code by sending spec...
Feb 1, 2023This vulnerability allows an attacker to write data beyond the intended memory buffer during Bluetooth mesh provisioning in Zephyr, potentially leadin...
Jul 26, 2022This vulnerability allows attackers to write predictable data to SMRAM (System Management Mode RAM) through a memory corruption flaw in InsydeH2O firm...
Feb 3, 2022This vulnerability allows attackers to write predictable data to SMRAM (System Management Mode RAM) in Insyde InsydeH2O UEFI firmware, potentially esc...
Feb 3, 2022This vulnerability allows an attacker to write predictable data to SMRAM (System Management Mode RAM) in Insyde InsydeH2O UEFI firmware, potentially l...
Feb 3, 2022This vulnerability in Insyde InsydeH2O firmware's System Management Mode (SMM) allows attackers with local access to execute arbitrary code with SMM p...
Jan 5, 2022This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service via an out-of-bounds write in WPS ...
Dec 26, 2021This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code via an out-of-bounds write in the WPS protocol implementation...
Dec 26, 2021This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service via an out-of-bounds write during ...
Dec 26, 2021CVE-2021-37569 is an out-of-bounds write vulnerability in MediaTek wireless chipsets that mishandle IEEE 1905 protocols. This allows attackers to pote...
Dec 26, 2021This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service through an out-of-bounds write in ...
Dec 26, 2021This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service through an out-of-bounds write in ...
Dec 26, 2021A heap-based buffer overflow vulnerability in the HomeKit setup process of ecobee3 lite smart thermostats allows attackers to force devices to connect...
Aug 3, 2021This vulnerability allows attackers to perform out-of-bounds memory writes by injecting specially crafted packets into Contiki-NG's RPL routing implem...
Jun 18, 2021This vulnerability allows a privileged guest user in QEMU virtual machines to trigger an out-of-bounds write in the virtio vhost-user GPU device. It c...
Jun 2, 2021This GRUB2 vulnerability allows attackers to corrupt memory by one byte for each quote in menu input due to an incorrect length calculation. It affect...
Mar 3, 2021This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...
Dec 9, 2025This vulnerability is a heap buffer overflow in MediaTek modem firmware that allows remote code execution when a device connects to a malicious base s...
Nov 4, 2025An out-of-bounds write vulnerability in QNAP operating systems allows authenticated remote attackers to modify or corrupt memory. This affects QNAP NA...
Aug 29, 2025An out-of-bounds write vulnerability in QNAP File Station 5 allows authenticated attackers to modify or corrupt memory. This could lead to arbitrary c...
Aug 18, 2025This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...
Apr 1, 2025This CVE describes an out-of-bounds write vulnerability in FreeType versions 2.13.0 and below when parsing TrueType GX and variable font files. The vu...
Mar 11, 2025This vulnerability in musl libc allows attackers to trigger an out-of-bounds write during EUC-KR to UTF-8 iconv conversion, potentially leading to mem...
Feb 14, 2025This vulnerability in MediaTek WLAN STA drivers allows remote attackers within wireless range to execute arbitrary code without user interaction. It a...
Jan 6, 2025This vulnerability allows remote attackers to execute arbitrary code on affected Samsung devices due to an out-of-bounds write in libsaped.so. It affe...
Dec 3, 2024A memory corruption vulnerability in Samsung Exynos baseband software allows attackers to write data beyond allocated buffer boundaries by exploiting ...
Dec 2, 2024CVE-2023-52724 is an out-of-bounds array access vulnerability in Open Networking Foundation SD-RAN's onos-kpimon component. This allows attackers to p...
Apr 30, 2024CVE-2024-1557 is a memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code through memory corruption. This affects...
Feb 20, 2024This vulnerability in Vyper smart contract language allows memory corruption when using specific builtin functions with complex expressions, potential...
Sep 18, 2023An out-of-bounds write vulnerability in Bitdefender Engines on Windows allows memory corruption that can crash the engine. This affects Bitdefender pr...
Jul 14, 2023This vulnerability allows attackers with network access to VMware vCenter Server to send specially crafted DCERPC packets causing memory corruption th...
Jun 22, 2023This CVE describes a heap overflow vulnerability in vCenter Server's DCERPC protocol implementation due to uninitialized memory usage. Attackers with ...
Jun 22, 2023This CVE allows remote attackers to execute arbitrary code on affected ArubaOS-Switch devices, potentially leading to complete system compromise. It a...
May 10, 2022This vulnerability allows remote attackers to execute arbitrary code on affected Mikrotik RouterOS devices by exploiting a heap-based buffer overflow ...
Mar 16, 2022A stack buffer overflow vulnerability in QNAP NAS Multimedia Console allows attackers to execute arbitrary code on affected systems. This affects QNAP...
Nov 13, 2021This memory corruption vulnerability in macOS allows attackers in a privileged network position to execute arbitrary code on affected systems. It affe...
Sep 8, 2021This is a stack-based buffer overflow vulnerability in FreeBSD's ggatec daemon that allows remote code execution. Attackers in a privileged network po...
Aug 30, 2021CVE-2021-26221 is an out-of-bounds write vulnerability in ezXML's ezxml_new function that occurs when processing XML files after memory pool exhaustio...
Feb 8, 2021This vulnerability in TensorFlow Lite allows attackers with access to segment_ids_data to trigger out-of-bounds writes to heap-allocated buffers by in...
Sep 25, 2020This vulnerability in TensorFlow Lite allows memory corruption when processing models with unsorted segment IDs in segment sum operations. It affects ...
Sep 25, 2020CVE-2020-1912 is an out-of-bounds read/write vulnerability in Facebook's Hermes JavaScript engine that could allow attackers to execute arbitrary code...
Sep 9, 2020About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,934 CVEs classified as CWE-787, with 717 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free