CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,686
Total CVEs
609
Critical
1,864
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 307
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 137
7 Fedoraproject 94
8 Samsung 77
9 Siemens 69
10 Dlink 59

All Out-of-bounds Write CVEs (2,686)

CVE-2023-46540
9.8

This CVE describes a stack overflow vulnerability in the formNtp function of TOTOLINK X2000R routers running firmware version 1.0.0-B20230221.0948.web...

Oct 25, 2023
CVE-2023-46542
9.8

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code or cause denial of...

Oct 25, 2023
CVE-2023-46544
9.8

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers via the formWirelessTbl function. Attackers can exploit this to execute a...

Oct 25, 2023
CVE-2023-46546
9.8

CVE-2023-46546 is a critical stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code by sending...

Oct 25, 2023
CVE-2023-46369
9.8

CVE-2023-46369 is a critical stack overflow vulnerability in Tenda W18E routers that allows remote attackers to execute arbitrary code by sending spec...

Oct 25, 2023
CVE-2023-46371
9.8

This CVE describes a critical stack overflow vulnerability in TP-Link routers that allows remote code execution. Attackers can exploit the upgradeInfo...

Oct 25, 2023
CVE-2023-34048
9.8

CVE-2023-34048 is a critical out-of-bounds write vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. A...

Oct 25, 2023
CVE-2023-45984
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected TOTOLINK routers via a stack overflow in the setLanguageCfg function....

Oct 16, 2023
CVE-2023-45580
9.8

A buffer overflow vulnerability in multiple D-Link router models allows remote attackers to execute arbitrary code via specific parameters in the ddns...

Oct 16, 2023
CVE-2023-45576
9.8

This CVE describes a critical buffer overflow vulnerability in multiple D-Link router models that allows remote attackers to execute arbitrary code wi...

Oct 16, 2023
CVE-2023-45578
9.8

A buffer overflow vulnerability in multiple D-Link router models allows remote attackers to execute arbitrary code by sending specially crafted reques...

Oct 16, 2023
CVE-2023-45573
9.8

A critical buffer overflow vulnerability in multiple D-Link router models allows remote attackers to execute arbitrary code by exploiting the 'n' para...

Oct 16, 2023
CVE-2023-45575
9.8

A critical stack overflow vulnerability in multiple D-Link router models allows remote attackers to execute arbitrary code via the ip parameter in the...

Oct 16, 2023
CVE-2023-36955
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK CP300+ routers by exploiting a stack overflow in the UploadCustomModu...

Oct 16, 2023
CVE-2023-36340
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK NR1800X routers by exploiting a stack overflow in the loginAuth funct...

Oct 16, 2023
CVE-2023-36952
9.8

CVE-2023-36952 is a critical stack overflow vulnerability in TOTOLINK CP300+ routers that allows remote attackers to execute arbitrary code by sending...

Oct 16, 2023
CVE-2023-35662
9.8

CVE-2023-35662 is a critical buffer overflow vulnerability in Android Pixel devices that allows remote attackers to execute arbitrary code without use...

Oct 11, 2023
CVE-2023-35646
9.8

This critical vulnerability allows remote attackers to execute arbitrary code without authentication or user interaction by exploiting a stack buffer ...

Oct 11, 2023
CVE-2023-44807
9.8

This vulnerability in D-Link DIR-820L routers allows remote attackers to execute arbitrary code via a stack overflow in the cancelPing function. Attac...

Oct 6, 2023
CVE-2023-20819
9.8

This vulnerability in the CDMA PPP protocol allows remote attackers to execute arbitrary code without user interaction by exploiting an out-of-bounds ...

Oct 2, 2023
CVE-2023-43869
9.8

CVE-2023-43869 is a critical buffer overflow vulnerability in D-Link DIR-619L B1 routers that allows remote attackers to execute arbitrary code or cau...

Sep 28, 2023
CVE-2023-5168
9.8

This vulnerability allows a compromised content process in Firefox to trigger an out-of-bounds write in the FilterNodeD2D1 component, potentially lead...

Sep 27, 2023
CVE-2023-5176
9.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Sep 27, 2023
CVE-2023-40163
9.8

CVE-2023-40163 is a critical out-of-bounds write vulnerability in Accusoft ImageGear's JPEG decoding functionality that allows memory corruption via s...

Sep 25, 2023
CVE-2023-43237
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 A2 routers via a stack overflow in the setMAC function. Attacke...

Sep 21, 2023
CVE-2023-43239
9.8

This vulnerability is a stack overflow in D-Link DIR-816 A2 routers that allows remote attackers to execute arbitrary code via the flag_5G parameter i...

Sep 21, 2023
CVE-2023-43241
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-823G routers via a stack overflow in the SetWLanRadioSecurity funct...

Sep 21, 2023
CVE-2023-43235
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-823G routers via a stack overflow in the SetWifiDownSettings functi...

Sep 21, 2023
CVE-2023-43200
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DI-7200GV2.E1 routers via a stack overflow in the yyxz.data function's ...

Sep 20, 2023
CVE-2023-43196
9.8

This CVE describes a critical stack overflow vulnerability in D-Link DI-7200GV2.E1 routers that allows remote attackers to execute arbitrary code via ...

Sep 20, 2023
CVE-2023-43198
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected D-Link DI-7200GV2.E1 routers via a stack overflow in the H5/hi_block....

Sep 20, 2023
CVE-2023-3935
9.8

CVE-2023-3935 is a critical heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service that allows unauthenticated remote attackers ...

Sep 13, 2023
CVE-2023-40942
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers via a stack overflow in the firewall configuration endpoint....

Sep 7, 2023
CVE-2023-40841
9.8

CVE-2023-40841 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial...

Aug 30, 2023
CVE-2023-40843
9.8

This CVE describes a critical buffer overflow vulnerability in Tenda AC6 routers. Attackers can exploit this to execute arbitrary code or cause denial...

Aug 30, 2023
CVE-2023-40845
9.8

This CVE describes a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code. Attackers can...

Aug 30, 2023
CVE-2023-40848
9.8

CVE-2023-40848 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial...

Aug 30, 2023
CVE-2023-41558
9.8

CVE-2023-41558 is a critical stack overflow vulnerability in Tenda AC7 routers that allows remote attackers to execute arbitrary code by sending speci...

Aug 30, 2023
CVE-2023-41560
9.8

CVE-2023-41560 is a critical stack-based buffer overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by ...

Aug 30, 2023
CVE-2023-41562
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the PowerSaveSet function. Atta...

Aug 30, 2023
CVE-2023-41552
9.8

This CVE describes a critical stack overflow vulnerability in Tenda AC7 and AC9 routers that allows remote code execution. Attackers can exploit this ...

Aug 30, 2023
CVE-2023-41554
9.8

CVE-2023-41554 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending speci...

Aug 30, 2023
CVE-2023-41556
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the SetIpMacBind function. Atta...

Aug 30, 2023
CVE-2023-40889
9.8

A heap-based buffer overflow vulnerability in ZBar's QR code scanning library allows attackers to execute arbitrary code or disclose sensitive informa...

Aug 29, 2023
CVE-2023-40846
9.8

CVE-2023-40846 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial...

Aug 28, 2023
CVE-2023-40799
9.8

CVE-2023-40799 is a critical buffer overflow vulnerability in Tenda AC23 routers that allows remote attackers to execute arbitrary code or cause denia...

Aug 25, 2023
CVE-2022-48174
9.8

A stack overflow vulnerability in BusyBox's ash shell allows remote attackers to execute arbitrary code via crafted commands. This affects all systems...

Aug 22, 2023
CVE-2021-32292
9.8

This is a stack buffer overflow vulnerability in json-c's auxiliary sample program json_parse. It allows attackers to execute arbitrary code or cause ...

Aug 22, 2023
CVE-2021-33388
9.8

CVE-2021-33388 is a heap buffer overflow vulnerability in dpic's makevar() function that allows attackers to execute arbitrary code or cause denial of...

Aug 22, 2023
CVE-2023-38961
9.8

A buffer overflow vulnerability in JerryScript v3.0.0 allows remote attackers to execute arbitrary code by exploiting the scanner_is_context_needed co...

Aug 21, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,686 CVEs classified as CWE-787, with 609 rated critical and 1,864 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free