CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,650
Total CVEs
608
Critical
1,829
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 302
2 Linux 228
3 Tenda 189
4 Adobe 186
5 Apple 161
6 Debian 134
7 Fedoraproject 91
8 Samsung 77
9 Siemens 68
10 Dlink 59

All Out-of-bounds Write CVEs (2,650)

CVE-2023-42115
9.8

CVE-2023-42115 is a critical out-of-bounds write vulnerability in Exim's SMTP service that allows unauthenticated remote attackers to execute arbitrar...

May 3, 2024
CVE-2024-33835
9.8

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code by sending specially cr...

May 1, 2024
CVE-2024-21894
9.8

A heap overflow vulnerability in the IPSec component of Ivanti Connect Secure and Policy Secure gateways allows unauthenticated attackers to send spec...

Apr 4, 2024
CVE-2024-30620
9.8

This vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code via a stack overflow in the serviceName parameter. Attack...

Apr 2, 2024
CVE-2024-31002
9.8

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows remote attackers to execute arbitrary code via the AP4 BitReader::ReadCache() function. Th...

Apr 2, 2024
CVE-2024-2615
9.8

CVE-2024-2615 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code by exploiting memory corruptio...

Mar 19, 2024
CVE-2023-42789
9.8

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices via specially crafted HTTP requ...

Mar 12, 2024
CVE-2024-28535
9.8

CVE-2024-28535 is a critical stack overflow vulnerability in Tenda AC18 routers that allows remote code execution. Attackers can exploit the mitInterf...

Mar 12, 2024
CVE-2024-27227
9.8

CVE-2024-27227 is a critical memory corruption vulnerability in Android's DNS handling that allows remote attackers to execute arbitrary code or cause...

Mar 11, 2024
CVE-2024-0039
9.8

This critical vulnerability in Android's Bluetooth stack allows remote attackers to execute arbitrary code without user interaction or additional priv...

Mar 11, 2024
CVE-2024-2184
9.8

A buffer overflow vulnerability in the WSD probe request process of certain Canon multifunction and laser printers allows an attacker on the same netw...

Mar 11, 2024
CVE-2023-7243
9.8

This vulnerability allows remote code execution through an out-of-bounds write in the ICSNPP Ethercat Zeek plugin when parsing specific Ethercat datag...

Mar 1, 2024
CVE-2024-0031
9.8

This CVE describes a critical Bluetooth protocol vulnerability in Android's ATT (Attribute Protocol) implementation. An out-of-bounds write due to imp...

Feb 16, 2024
CVE-2024-21762
9.8

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices via specially crafted requests....

Feb 9, 2024
CVE-2024-24188
9.8

CVE-2024-24188 is a critical heap buffer overflow vulnerability in Jsish v3.5.0 that allows attackers to execute arbitrary code or cause denial of ser...

Feb 7, 2024
CVE-2024-1283
9.8

A heap buffer overflow vulnerability in Chrome's Skia graphics engine allows remote attackers to potentially exploit heap corruption via a crafted HTM...

Feb 7, 2024
CVE-2024-0244
9.8

A buffer overflow vulnerability in the CPCA PCFAX number process of Canon multifunction printers allows network attackers to crash devices or execute ...

Feb 6, 2024
CVE-2023-6229
9.8

A buffer overflow vulnerability in the CPCA PDL Resource Download process of Canon multifunction printers and laser printers allows network attackers ...

Feb 6, 2024
CVE-2023-6231
9.8

A critical buffer overflow vulnerability in the WSD probe request process of Canon multifunction printers allows attackers on the same network segment...

Feb 6, 2024
CVE-2023-6233
9.8

A buffer overflow vulnerability in the SLP attribute request process of Canon multifunction printers and laser printers allows attackers on the same n...

Feb 6, 2024
CVE-2024-24543
9.8

A buffer overflow vulnerability in the setSchedWifi function of Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code or cause den...

Feb 5, 2024
CVE-2024-23978
9.8

A heap-based buffer overflow vulnerability in HOME SPOT CUBE2 routers allows attackers to execute arbitrary code by sending specially crafted invalid ...

Feb 2, 2024
CVE-2023-51889
9.8

A stack overflow vulnerability in Mathtex v1.05 and earlier allows remote attackers to execute arbitrary code by sending a specially crafted string in...

Jan 24, 2024
CVE-2024-22662
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting a stack overflow in the setParentalRules...

Jan 23, 2024
CVE-2023-6816
9.8

This vulnerability in X.Org server allows heap overflow when button mapping exceeds allocated memory space. Attackers could exploit this to execute ar...

Jan 18, 2024
CVE-2024-22916
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected D-LINK Go-RT-AC750 routers via a stack overflow in the cgibin compone...

Jan 16, 2024
CVE-2023-49351
9.8

A stack-based buffer overflow vulnerability in the /bin/webs binary of Edimax BR6478AC V2 routers allows attackers to execute arbitrary code or crash ...

Jan 16, 2024
CVE-2024-21591
9.8

An out-of-bounds write vulnerability in Juniper J-Web interface allows unauthenticated attackers to execute arbitrary code with root privileges or cau...

Jan 12, 2024
CVE-2023-31488
9.8

This critical vulnerability in Hyland Perceptive Filters allows attackers to execute arbitrary code by sending a specially crafted document that trigg...

Jan 10, 2024
CVE-2023-51970
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attacke...

Jan 10, 2024
CVE-2023-51962
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the setIptvInfo functio...

Jan 10, 2024
CVE-2023-51968
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the getIptvInfo function. Attacke...

Jan 10, 2024
CVE-2023-51954
9.8

CVE-2023-51954 is a critical stack overflow vulnerability in Tenda AX1803 routers that allows remote attackers to execute arbitrary code by sending sp...

Jan 10, 2024
CVE-2023-51956
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attacke...

Jan 10, 2024
CVE-2023-51958
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formGetIptv function. Attacke...

Jan 10, 2024
CVE-2023-51960
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formGetIptv function. Attacke...

Jan 10, 2024
CVE-2023-51964
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the setIptvInfo functio...

Jan 10, 2024
CVE-2023-51952
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers via a stack overflow in the formSetIptv function. Attacke...

Jan 10, 2024
CVE-2023-51961
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the formGetIptv functio...

Jan 10, 2024
CVE-2023-51971
9.8

CVE-2023-51971 is a critical stack overflow vulnerability in Tenda AX1803 routers that allows remote attackers to execute arbitrary code by sending sp...

Jan 10, 2024
CVE-2020-13880
9.8

CVE-2020-13880 is a critical heap-based out-of-bounds write vulnerability in IrfanView's B3D plugin that allows remote code execution. Attackers can e...

Jan 5, 2024
CVE-2020-13878
9.8

CVE-2020-13878 is a critical heap-based out-of-bounds write vulnerability in IrfanView's B3D plugin that allows remote code execution. Attackers can e...

Jan 5, 2024
CVE-2024-22086
9.8

CVE-2024-22086 is a critical stack-based buffer overflow vulnerability in cherry's HTTP request handler that allows remote attackers to execute arbitr...

Jan 5, 2024
CVE-2023-32874
9.8

CVE-2023-32874 is a critical out-of-bounds write vulnerability in the Modem IMS Stack that allows remote code execution without user interaction or ad...

Jan 2, 2024
CVE-2023-51135
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the password setup f...

Dec 30, 2023
CVE-2023-52173
9.8

CVE-2023-52173 is a critical out-of-bounds write vulnerability in XnView Classic for Windows that allows attackers to execute arbitrary code by trigge...

Dec 29, 2023
CVE-2023-51084
9.8

This vulnerability in hyavijava v6.0.07.1 allows remote attackers to execute arbitrary code via a stack overflow in the ResultConverter.convert2Xml me...

Dec 27, 2023
CVE-2023-51090
9.8

CVE-2023-51090 is a critical stack overflow vulnerability in Tenda M3 routers that allows remote attackers to execute arbitrary code by sending specia...

Dec 26, 2023
CVE-2023-51092
9.8

This CVE describes a stack overflow vulnerability in Tenda M3 routers that allows remote attackers to execute arbitrary code via the upgrade function....

Dec 26, 2023
CVE-2023-51102
9.8

CVE-2023-51102 is a critical stack overflow vulnerability in Tenda W9 routers that allows remote attackers to execute arbitrary code or cause denial o...

Dec 26, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,650 CVEs classified as CWE-787, with 608 rated critical and 1,829 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free