CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,969
Total CVEs
732
Critical
2,024
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 369
2 Linux 228
3 Adobe 218
4 Apple 200
5 Tenda 189
6 Debian 167
7 Fedoraproject 117
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,969)

CVE-2025-40809
7.8

An out-of-bounds write vulnerability in Solid Edge SE2024 and SE2025 allows attackers to crash the application or execute arbitrary code by tricking u...

Oct 14, 2025
CVE-2025-20723
7.8

This CVE describes an out-of-bounds write vulnerability in the GNSS driver that allows local privilege escalation. Attackers with initial System privi...

Oct 14, 2025
CVE-2025-20715
7.8

This CVE describes an out-of-bounds write vulnerability in MediaTek's wlan AP driver due to incorrect bounds checking. It allows local privilege escal...

Oct 14, 2025
CVE-2025-61858
7.8

An out-of-bounds write vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to execute arbitrary code by tricking users into opening malicious...

Oct 10, 2025
CVE-2025-39962
7.8

This CVE-2025-39962 is an integer overflow vulnerability in the Linux kernel's rxrpc subsystem that could allow local attackers to cause denial of ser...

Oct 9, 2025
CVE-2025-47355
7.8

This vulnerability allows memory corruption through improper handling of remote procedure IOCTL calls, potentially leading to arbitrary code execution...

Oct 9, 2025
CVE-2023-53680
7.8

A Linux kernel vulnerability in NFSD (Network File System Daemon) allows out-of-bounds array access when processing malformed NFSv4 compound operation...

Oct 7, 2025
CVE-2023-53652
7.8

This CVE-2023-53652 is an out-of-bounds read vulnerability in the Linux kernel's vDPA (virtual Data Path Acceleration) subsystem. It allows attackers ...

Oct 7, 2025
CVE-2022-50526
7.8

A memory corruption vulnerability in the Linux kernel's DisplayPort driver allows attackers to write beyond allocated buffer boundaries when too many ...

Oct 7, 2025
CVE-2023-53541
7.8

This vulnerability in the Linux kernel's MTD subsystem allows potential out-of-bounds memory access when writing OOB (out-of-band) data to NAND flash ...

Oct 4, 2025
CVE-2025-39952
7.8

This CVE describes a buffer overflow vulnerability in the wilc1000 WiFi driver in the Linux kernel. An attacker could exploit this to execute arbitrar...

Oct 4, 2025
CVE-2025-39935
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's SMA1307 audio codec driver. An attacker could exploit this to cause kernel ...

Oct 4, 2025
CVE-2025-39939
7.8

A memory corruption vulnerability in the Linux kernel's s390 IOMMU subsystem allows reading from or writing to arbitrary memory locations when using i...

Oct 4, 2025
CVE-2025-59299
7.8

Delta Electronics DIAScreen has a file parsing vulnerability where opening a malicious file can lead to out-of-bounds write and arbitrary code executi...

Oct 3, 2025
CVE-2025-59300
7.8

Delta Electronics DIAScreen has a file parsing vulnerability that allows out-of-bounds write when processing malicious files. This enables attackers t...

Oct 3, 2025
CVE-2025-59297
7.8

Delta Electronics DIAScreen has a file parsing vulnerability that allows out-of-bounds write when processing malicious files. An attacker can exploit ...

Oct 3, 2025
CVE-2023-53516
7.8

A missing length validation in the Linux kernel's macvlan driver allows attackers to trigger a heap out-of-bounds read by providing malformed network ...

Oct 1, 2025
CVE-2023-53495
7.8

This vulnerability in the Linux kernel's Marvell PP2 Ethernet driver allows local attackers to trigger an out-of-bounds write or NULL pointer derefere...

Oct 1, 2025
CVE-2022-50437
7.8

A memory corruption vulnerability in the Linux kernel's DRM/MSM HDMI driver allows attackers to write beyond allocated memory boundaries when more tha...

Oct 1, 2025
CVE-2025-39917
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's BPF crypto subsystem. It allows root-privileged users to write beyond al...

Oct 1, 2025
CVE-2025-6033
7.8

A memory corruption vulnerability in NI Circuit Design Suite's SymbolEditor allows attackers to execute arbitrary code or disclose information by tric...

Sep 30, 2025
CVE-2025-39888
7.8

A memory corruption vulnerability in the Linux kernel's FUSE filesystem implementation allows attackers to write beyond allocated memory boundaries. T...

Sep 23, 2025
CVE-2025-39849
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's WiFi subsystem where SSID length validation is missing in the __cfg80211_co...

Sep 19, 2025
CVE-2025-39837
7.8

A race condition vulnerability in the ASUS WMI driver for Linux kernel allows concurrent driver registrations to corrupt memory, potentially causing k...

Sep 19, 2025
CVE-2025-39841
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's lpfc SCSI driver. An attacker could exploit this to cause a kernel panic (deni...

Sep 19, 2025
CVE-2022-50410
7.8

This vulnerability in the Linux kernel's NFS server allows attackers to overflow send buffers by sending excessively large RPC Call messages. This aff...

Sep 18, 2025
CVE-2022-50406
7.8

CVE-2022-50406 is a memory corruption vulnerability in the Linux kernel's iomap subsystem that occurs when recording errors during writeback operation...

Sep 18, 2025
CVE-2023-53372
7.8

This CVE-2023-53372 is a buffer overflow vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation. It allows att...

Sep 18, 2025
CVE-2022-50368
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's DRM/MSM DSI driver where missing bounds checking allows writing beyond a fi...

Sep 17, 2025
CVE-2023-53331
7.8

This vulnerability in the Linux kernel's pstore/ram subsystem allows a local attacker to cause a kernel panic (system crash) by triggering a write to ...

Sep 16, 2025
CVE-2023-53320
7.8

A memory corruption vulnerability in the Linux kernel's mpi3mr SCSI driver allows attackers to trigger a kernel out-of-bounds write via specially craf...

Sep 16, 2025
CVE-2025-39821
7.8

A Linux kernel vulnerability in the perf subsystem allows undefined behavior when handling disabled performance monitoring events during throttling. T...

Sep 16, 2025
CVE-2025-39809
7.8

A stack buffer overflow vulnerability in the Linux kernel's Intel QuickI2C driver allows local attackers to write beyond allocated memory bounds. This...

Sep 16, 2025
CVE-2023-53274
7.8

A memory corruption vulnerability in the Linux kernel's MediaTek MT8183 clock driver allows out-of-bounds writes when using the simple-probe mechanism...

Sep 16, 2025
CVE-2023-53205
7.8

This CVE-2023-53205 is a race condition vulnerability in the Linux kernel's KVM s390 diag 9c handler that could allow out-of-bounds memory access. It ...

Sep 15, 2025
CVE-2022-50325
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's ASoC Intel AVS driver. An attacker could exploit this to cause memory corrupt...

Sep 15, 2025
CVE-2022-50320
7.8

This CVE-2022-50320 is a kernel memory corruption vulnerability in the Linux kernel's ACPI FPDT table handling. It allows attackers to trigger a kerne...

Sep 15, 2025
CVE-2023-53184
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's ARM64 SME/SVE implementation. When changing vector lengths, the kernel inco...

Sep 15, 2025
CVE-2023-53179
7.8

A missing macro in the Linux kernel's netfilter ipset module causes integer underflow when calculating array offsets, leading to slab out-of-bounds me...

Sep 15, 2025
CVE-2022-50258
7.8

This is a stack buffer overflow vulnerability in the Linux kernel's Broadcom WiFi driver (brcmfmac). It allows attackers to read kernel memory beyond ...

Sep 15, 2025
CVE-2025-39788
7.8

A Linux kernel vulnerability in the UFS (Universal Flash Storage) driver for Exynos chipsets allows undefined behavior due to integer overflow when pr...

Sep 11, 2025
CVE-2025-39783
7.8

A use-after-free vulnerability in the Linux kernel's PCI endpoint subsystem allows local attackers to potentially crash the system or execute arbitrar...

Sep 11, 2025
CVE-2025-54243
7.8

CVE-2025-54243 is an out-of-bounds write vulnerability in Substance3D Viewer that could allow arbitrary code execution when a user opens a malicious f...

Sep 9, 2025
CVE-2025-54245
7.8

Substance3D Viewer versions 0.25.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user open...

Sep 9, 2025
CVE-2025-39723
7.8

A Linux kernel vulnerability in the netfs subsystem's unbuffered write error handling can cause kernel NULL pointer dereferences when all subrequests ...

Sep 5, 2025
CVE-2025-38730
7.8

A Linux kernel vulnerability in io_uring's networking component allows memory corruption when using ring-provided buffers with partial retries. This a...

Sep 4, 2025
CVE-2025-38702
7.8

A buffer overflow vulnerability exists in the Linux kernel's framebuffer device driver (fbdev) in the do_register_framebuffer() function. This allows ...

Sep 4, 2025
CVE-2025-38685
7.8

This vulnerability in the Linux kernel's fbdev subsystem allows a local user to trigger an out-of-bounds write in the fast_imageblit function when per...

Sep 4, 2025
CVE-2025-36903
7.8

CVE-2025-36903 is a memory corruption vulnerability in Android's lwis_io_buffer_write function that allows local privilege escalation without user int...

Sep 4, 2025
CVE-2024-49730
7.8

This vulnerability allows local privilege escalation on Android devices through a memory corruption flaw in FuseDaemon.cpp. An attacker could gain ele...

Sep 2, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,969 CVEs classified as CWE-787, with 732 rated critical and 2,024 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free