CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,668
Total CVEs
608
Critical
1,847
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 305
2 Linux 228
3 Adobe 192
4 Tenda 189
5 Apple 161
6 Debian 135
7 Fedoraproject 92
8 Samsung 77
9 Siemens 69
10 Dlink 59

All Out-of-bounds Write CVEs (2,668)

CVE-2023-51095
9.8

Tenda M3 routers running firmware version 1.0.0.12(4856) contain a stack-based buffer overflow vulnerability in the formDelWlRfPolicy function. This a...

Dec 26, 2023
CVE-2023-50992
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda i29 routers by exploiting a stack overflow in the setPing function's ip ...

Dec 20, 2023
CVE-2023-50985
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda i29 routers via a buffer overflow in the lanCfgSet function. Attackers c...

Dec 20, 2023
CVE-2023-50987
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda i29 routers by sending specially crafted requests to the sysTimeInfoSet ...

Dec 20, 2023
CVE-2023-46261
9.8

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted data packets that cause memory corruption, potentia...

Dec 19, 2023
CVE-2023-46224
9.8

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially l...

Dec 19, 2023
CVE-2023-46257
9.8

This critical vulnerability in Mobile Device Server allows remote attackers to send specially crafted packets that cause memory corruption, potentiall...

Dec 19, 2023
CVE-2023-46259
9.8

CVE-2023-46259 is a critical memory corruption vulnerability in the Mobile Device Server component of Ivanti Avalanche. Attackers can send specially c...

Dec 19, 2023
CVE-2023-46216
9.8

CVE-2023-46216 is a critical memory corruption vulnerability in the Mobile Device Server component of Ivanti Avalanche. Attackers can send specially c...

Dec 19, 2023
CVE-2023-46220
9.8

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially l...

Dec 19, 2023
CVE-2023-46222
9.8

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially l...

Dec 19, 2023
CVE-2023-41727
9.8

This critical vulnerability in the Mobile Device Server allows attackers to send specially crafted packets that cause memory corruption, potentially l...

Dec 19, 2023
CVE-2023-50965
9.8

This vulnerability in MicroHttpServer allows attackers to trigger a stack-based buffer overflow by sending an excessively long URI. This can lead to r...

Dec 17, 2023
CVE-2023-49417
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLink A7000R routers via a stack overflow in the setOpModeCfg function. Att...

Dec 11, 2023
CVE-2023-46932
9.8

A heap buffer overflow vulnerability in GPAC's MP4Box allows attackers to execute arbitrary code or cause denial of service by exploiting the str2ulon...

Dec 9, 2023
CVE-2023-48423
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. The flaw exists in the DHCP...

Dec 8, 2023
CVE-2023-49007
9.8

A stack-based buffer overflow vulnerability exists in the httpd service of Netgear Orbi RBR750 routers running firmware versions before V7.2.6.21. Thi...

Dec 8, 2023
CVE-2023-49402
9.8

CVE-2023-49402 is a critical stack overflow vulnerability in Tenda W30E routers that allows remote attackers to execute arbitrary code or cause denial...

Dec 7, 2023
CVE-2023-49410
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers via a stack overflow in the set_wan_status function. Attack...

Dec 7, 2023
CVE-2023-50000
9.8

This CVE describes a stack overflow vulnerability in Tenda W30E routers via the formResetMeshNode function. Attackers can exploit this to execute arbi...

Dec 7, 2023
CVE-2023-50002
9.8

This CVE describes a stack overflow vulnerability in Tenda W30E routers that allows remote attackers to execute arbitrary code or cause denial of serv...

Dec 7, 2023
CVE-2023-49433
9.8

Tenda AX9 routers running firmware V22.03.01.46 contain a stack overflow vulnerability in the SetVirtualServerCfg function. Attackers can exploit this...

Dec 7, 2023
CVE-2023-49425
9.8

CVE-2023-49425 is a critical stack overflow vulnerability in Tenda AX12 routers that allows remote attackers to execute arbitrary code by sending spec...

Dec 7, 2023
CVE-2023-49424
9.8

CVE-2023-49424 is a critical stack overflow vulnerability in Tenda AX12 routers that allows remote attackers to execute arbitrary code by sending spec...

Dec 7, 2023
CVE-2023-48316
9.8

Azure RTOS NetX Duo contains memory overflow vulnerabilities in SNMP, SMTP, FTP, and DTLS components that allow remote code execution. This affects al...

Dec 5, 2023
CVE-2023-40078
9.8

This vulnerability allows a paired Bluetooth device to execute arbitrary code on an Android device without user interaction. It affects Android device...

Dec 4, 2023
CVE-2023-45480
9.8

CVE-2023-45480 is a critical stack-based buffer overflow vulnerability in Tenda AC10 routers. Attackers can exploit this by sending specially crafted ...

Nov 29, 2023
CVE-2023-45482
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a stack overflow in the get_parentControl_list_Info fun...

Nov 29, 2023
CVE-2023-45484
9.8

This vulnerability is a stack overflow in Tenda AC10 routers via the shareSpeed parameter in the fromSetWifiGuestBasic function. It allows remote atta...

Nov 29, 2023
CVE-2023-49044
9.8

A stack overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the ...

Nov 27, 2023
CVE-2023-49043
9.8

A buffer overflow vulnerability in Tenda AX1803 routers allows remote attackers to execute arbitrary code by sending specially crafted data to the wpa...

Nov 27, 2023
CVE-2023-29075
9.8

This vulnerability allows attackers to exploit a memory corruption flaw in Autodesk AutoCAD by tricking users into opening malicious PRT files. Succes...

Nov 23, 2023
CVE-2023-41101
9.8

This vulnerability in OpenNDS captive portal allows attackers to trigger buffer overflows via specially crafted GET requests. It affects OpenNDS versi...

Nov 17, 2023
CVE-2023-39281
9.8

This vulnerability allows attackers to execute arbitrary code during the DXE phase of system boot by exploiting a stack buffer overflow in AsfSecureBo...

Nov 1, 2023
CVE-2023-5730
9.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Oct 25, 2023
CVE-2023-46563
9.8

This vulnerability is a stack overflow in the formIpQoS function of TOTOLINK X2000R routers running firmware version v1.0.0-B20230221.0948.web. It all...

Oct 25, 2023
CVE-2023-46548
9.8

This CVE describes a stack overflow vulnerability in the TOTOLINK X2000R router's web interface function formWlanRedirect. Attackers can exploit this ...

Oct 25, 2023
CVE-2023-46550
9.8

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code. The vulnerability...

Oct 25, 2023
CVE-2023-46552
9.8

This vulnerability is a stack overflow in the formMultiAP function of TOTOLINK X2000R routers, allowing remote attackers to execute arbitrary code or ...

Oct 25, 2023
CVE-2023-46554
9.8

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers via the formMapDel function, allowing remote code execution. Attackers ca...

Oct 25, 2023
CVE-2023-46556
9.8

This vulnerability is a stack overflow in the formFilter function of TOTOLINK X2000R routers running firmware version 1.0.0-B20230221.0948.web. It all...

Oct 25, 2023
CVE-2023-46558
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the formMapDelDevice...

Oct 25, 2023
CVE-2023-46560
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the formTcpipSetup f...

Oct 25, 2023
CVE-2023-46518
9.8

Mercury A15 V1.0 firmware version 20230818_1.0.3 contains a command execution vulnerability in the cloudDeviceTokenSuccCB component that allows remote...

Oct 25, 2023
CVE-2023-46521
9.8

This vulnerability in TP-LINK TL-WR886N routers allows remote attackers to execute arbitrary code via a stack overflow in the RegisterRegister functio...

Oct 25, 2023
CVE-2023-46523
9.8

This vulnerability is a stack overflow in the upgradeInfoRegister function of TP-LINK TL-WR886N routers, allowing remote attackers to execute arbitrar...

Oct 25, 2023
CVE-2023-46526
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR886N routers via a stack overflow in the resetCloudPwdRegister fu...

Oct 25, 2023
CVE-2023-46534
9.8

This vulnerability in TP-LINK TL-WR886N routers allows remote attackers to execute arbitrary code via a stack overflow in the modifyAccPwdRegister fun...

Oct 25, 2023
CVE-2023-46536
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR886N routers via a stack overflow in the chkRegVeriRegister funct...

Oct 25, 2023
CVE-2023-46538
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR886N routers via a stack overflow in the chkResetVeriRegister fun...

Oct 25, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,668 CVEs classified as CWE-787, with 608 rated critical and 1,847 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free