CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,934
Total CVEs
717
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 362
2 Linux 228
3 Adobe 214
4 Apple 194
5 Tenda 189
6 Debian 163
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,934)

CVE-2024-39927
8.2

This CVE describes an out-of-bounds write vulnerability in Ricoh MFPs and printers that allows remote attackers to send specially crafted requests. Ex...

Jul 10, 2024
CVE-2024-37185
8.2

This vulnerability allows remote attackers to execute arbitrary code in pre-installed applications on OpenHarmony devices through an out-of-bounds wri...

Jul 2, 2024
CVE-2024-24956
8.2

This CVE describes an out-of-bounds write vulnerability in AutomationDirect P3-550E programming software that allows remote attackers to cause heap-ba...

May 28, 2024
CVE-2024-24946
8.2

A heap-based buffer overflow vulnerability in AutomationDirect P3-550E programming software allows unauthenticated attackers to send specially crafted...

May 28, 2024
CVE-2024-24954
8.2

This vulnerability allows remote attackers to write arbitrary null bytes to heap memory in AutomationDirect P3-550E PLC programming software. Exploita...

May 28, 2024
CVE-2022-23085
8.2

CVE-2022-23085 is an integer overflow vulnerability in FreeBSD's netmap subsystem that allows kernel memory corruption. A privileged process within a ...

Feb 15, 2024
CVE-2023-21499
8.2

This vulnerability allows local attackers to execute arbitrary code on affected Samsung devices by exploiting an out-of-bounds write in the mPOS TUI t...

May 4, 2023
CVE-2023-20869
8.2

This vulnerability allows attackers to execute arbitrary code on the host system by exploiting a stack-based buffer overflow in VMware's Bluetooth sha...

Apr 25, 2023
CVE-2022-30904
8.2

A buffer overflow vulnerability in Bestechnic Bluetooth Mesh SDK allows attackers to execute arbitrary code during device provisioning by sending spec...

Feb 1, 2023
CVE-2022-31364
8.2

CVE-2022-31364 is a buffer overflow vulnerability in Cypress Bluetooth Mesh SDK that allows remote attackers to execute arbitrary code by sending spec...

Feb 1, 2023
CVE-2022-1041
8.2

This vulnerability allows an attacker to write data beyond the intended memory buffer during Bluetooth mesh provisioning in Zephyr, potentially leadin...

Jul 26, 2022
CVE-2021-42554
8.2

This vulnerability allows attackers to write predictable data to SMRAM (System Management Mode RAM) through a memory corruption flaw in InsydeH2O firm...

Feb 3, 2022
CVE-2021-43615
8.2

This vulnerability allows attackers to write predictable data to SMRAM (System Management Mode RAM) in Insyde InsydeH2O UEFI firmware, potentially esc...

Feb 3, 2022
CVE-2022-24031
8.2

This vulnerability allows an attacker to write predictable data to SMRAM (System Management Mode RAM) in Insyde InsydeH2O UEFI firmware, potentially l...

Feb 3, 2022
CVE-2021-45970
8.2

This vulnerability in Insyde InsydeH2O firmware's System Management Mode (SMM) allows attackers with local access to execute arbitrary code with SMM p...

Jan 5, 2022
CVE-2021-35055
8.2

This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service via an out-of-bounds write in WPS ...

Dec 26, 2021
CVE-2021-37561
8.2

This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code via an out-of-bounds write in the WPS protocol implementation...

Dec 26, 2021
CVE-2021-37563
8.2

This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service via an out-of-bounds write during ...

Dec 26, 2021
CVE-2021-37569
8.2

CVE-2021-37569 is an out-of-bounds write vulnerability in MediaTek wireless chipsets that mishandle IEEE 1905 protocols. This allows attackers to pote...

Dec 26, 2021
CVE-2021-37571
8.2

This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service through an out-of-bounds write in ...

Dec 26, 2021
CVE-2021-37583
8.2

This vulnerability in MediaTek Wi-Fi chipsets allows attackers to execute arbitrary code or cause denial of service through an out-of-bounds write in ...

Dec 26, 2021
CVE-2021-27954
8.2

A heap-based buffer overflow vulnerability in the HomeKit setup process of ecobee3 lite smart thermostats allows attackers to force devices to connect...

Aug 3, 2021
CVE-2021-21257
8.2

This vulnerability allows attackers to perform out-of-bounds memory writes by injecting specially crafted packets into Contiki-NG's RPL routing implem...

Jun 18, 2021
CVE-2021-3546
8.2

This vulnerability allows a privileged guest user in QEMU virtual machines to trigger an out-of-bounds write in the virtio vhost-user GPU device. It c...

Jun 2, 2021
CVE-2021-20233
8.2

This GRUB2 vulnerability allows attackers to corrupt memory by one byte for each quote in menu input due to an incorrect length calculation. It affect...

Mar 3, 2021
CVE-2025-14333
8.1

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Dec 9, 2025
CVE-2025-20727
8.1

This vulnerability is a heap buffer overflow in MediaTek modem firmware that allows remote code execution when a device connects to a malicious base s...

Nov 4, 2025
CVE-2025-30273
8.1

An out-of-bounds write vulnerability in QNAP operating systems allows authenticated remote attackers to modify or corrupt memory. This affects QNAP NA...

Aug 29, 2025
CVE-2025-47206
8.1

An out-of-bounds write vulnerability in QNAP File Station 5 allows authenticated attackers to modify or corrupt memory. This could lead to arbitrary c...

Aug 18, 2025
CVE-2025-3034
8.1

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Apr 1, 2025
CVE-2025-27363
KEV EPSS 76.7% 8.1

This CVE describes an out-of-bounds write vulnerability in FreeType versions 2.13.0 and below when parsing TrueType GX and variable font files. The vu...

Mar 11, 2025
CVE-2025-26519
8.1

This vulnerability in musl libc allows attackers to trigger an out-of-bounds write during EUC-KR to UTF-8 iconv conversion, potentially leading to mem...

Feb 14, 2025
CVE-2024-20146
8.1

This vulnerability in MediaTek WLAN STA drivers allows remote attackers within wireless range to execute arbitrary code without user interaction. It a...

Jan 6, 2025
CVE-2024-49415
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Samsung devices due to an out-of-bounds write in libsaped.so. It affe...

Dec 3, 2024
CVE-2024-39890
8.1

A memory corruption vulnerability in Samsung Exynos baseband software allows attackers to write data beyond allocated buffer boundaries by exploiting ...

Dec 2, 2024
CVE-2023-52724
8.1

CVE-2023-52724 is an out-of-bounds array access vulnerability in Open Networking Foundation SD-RAN's onos-kpimon component. This allows attackers to p...

Apr 30, 2024
CVE-2024-1557
8.1

CVE-2024-1557 is a memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code through memory corruption. This affects...

Feb 20, 2024
CVE-2023-42443
8.1

This vulnerability in Vyper smart contract language allows memory corruption when using specific builtin functions with complex expressions, potential...

Sep 18, 2023
CVE-2023-3633
8.1

An out-of-bounds write vulnerability in Bitdefender Engines on Windows allows memory corruption that can crash the engine. This affects Bitdefender pr...

Jul 14, 2023
CVE-2023-20894
8.1

This vulnerability allows attackers with network access to VMware vCenter Server to send specially crafted DCERPC packets causing memory corruption th...

Jun 22, 2023
CVE-2023-20892
8.1

This CVE describes a heap overflow vulnerability in vCenter Server's DCERPC protocol implementation due to uninitialized memory usage. Attackers with ...

Jun 22, 2023
CVE-2022-23677
8.1

This CVE allows remote attackers to execute arbitrary code on affected ArubaOS-Switch devices, potentially leading to complete system compromise. It a...

May 10, 2022
CVE-2021-41987
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Mikrotik RouterOS devices by exploiting a heap-based buffer overflow ...

Mar 16, 2022
CVE-2021-38684
8.1

A stack buffer overflow vulnerability in QNAP NAS Multimedia Console allows attackers to execute arbitrary code on affected systems. This affects QNAP...

Nov 13, 2021
CVE-2021-30717
8.1

This memory corruption vulnerability in macOS allows attackers in a privileged network position to execute arbitrary code on affected systems. It affe...

Sep 8, 2021
CVE-2021-29630
8.1

This is a stack-based buffer overflow vulnerability in FreeBSD's ggatec daemon that allows remote code execution. Attackers in a privileged network po...

Aug 30, 2021
CVE-2021-26221
8.1

CVE-2021-26221 is an out-of-bounds write vulnerability in ezXML's ezxml_new function that occurs when processing XML files after memory pool exhaustio...

Feb 8, 2021
CVE-2020-15212
8.1

This vulnerability in TensorFlow Lite allows attackers with access to segment_ids_data to trigger out-of-bounds writes to heap-allocated buffers by in...

Sep 25, 2020
CVE-2020-15214
8.1

This vulnerability in TensorFlow Lite allows memory corruption when processing models with unsorted segment IDs in segment sum operations. It affects ...

Sep 25, 2020
CVE-2020-1912
8.1

CVE-2020-1912 is an out-of-bounds read/write vulnerability in Facebook's Hermes JavaScript engine that could allow attackers to execute arbitrary code...

Sep 9, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,934 CVEs classified as CWE-787, with 717 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free