CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,381
Total CVEs
844
Critical
2,324
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
101
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 404
2 Adobe 290
3 Apple 247
4 Linux 232
5 Debian 195
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 90
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,381)

CVE-2021-43814
7.7

CVE-2021-43814 is a heap-based out-of-bounds write vulnerability in Rizin's parse_die() function when processing AMD64 ELF binaries with DWARF debug i...

Dec 13, 2021
CVE-2021-34375
7.7

CVE-2021-34375 is a stack cookie randomization vulnerability in NVIDIA Trusty trusted applications (TAs) that could allow stack-based buffer overflows...

Jun 30, 2021
CVE-2021-34379
7.7

This vulnerability in NVIDIA's Trusty HDCP service allows attackers to exploit missing bounds checking in command 10, potentially leading to memory co...

Jun 30, 2021
CVE-2025-68474
7.6

This CVE describes a buffer overflow vulnerability in the ESP-IDF BlueDroid AVRCP stack. An attacker could send specially crafted Bluetooth AVRCP comm...

Dec 27, 2025
CVE-2025-64129
7.6

Zenitel TCIV-3+ devices contain an out-of-bounds write vulnerability that allows remote attackers to crash the device through memory corruption. This ...

Nov 26, 2025
CVE-2025-0624
7.6

This CVE-2025-0624 vulnerability in grub2 allows remote attackers on the same network segment to execute arbitrary code during network boot by exploit...

Feb 19, 2025
CVE-2023-26073
7.6

A heap-based buffer overflow vulnerability in Samsung's 5G MM message codec allows remote code execution on affected mobile devices. Attackers can exp...

Mar 13, 2023
CVE-2023-26074
7.6

This vulnerability allows remote attackers to execute arbitrary code on affected Samsung mobile devices via a heap-based buffer overflow in the 5G mod...

Mar 13, 2023
CVE-2022-21740
7.6

CVE-2022-21740 is a heap overflow vulnerability in TensorFlow's SparseCountSparseOutput implementation that allows attackers to write beyond allocated...

Feb 3, 2022
CVE-2021-29073
7.6

This CVE describes a stack-based buffer overflow vulnerability in certain NETGEAR routers and WiFi systems that allows an authenticated attacker to ex...

Mar 23, 2021
CVE-2019-25478
7.5

CVE-2019-25478 is a buffer overflow vulnerability in GetGo Download Manager that allows remote attackers to cause denial of service by sending HTTP re...

Mar 11, 2026
CVE-2026-25990
7.5

Pillow versions 10.3.0 through 12.1.0 contain an out-of-bounds write vulnerability when processing specially crafted PSD image files. This could allow...

Feb 11, 2026
CVE-2026-25061
7.5

This vulnerability in tcpflow's wifipcap component allows a 1-byte out-of-bounds write when parsing specially crafted 802.11 management frames with la...

Jan 29, 2026
CVE-2026-24827
7.5

An out-of-bounds write vulnerability in Commander-Genius game engine allows attackers to write data beyond allocated memory boundaries. This affects a...

Jan 27, 2026
CVE-2021-47786
7.5

This vulnerability in Redragon Gaming Mouse drivers allows attackers to cause a kernel-level denial of service by sending specially crafted IOCTL requ...

Jan 16, 2026
CVE-2025-13151
7.5

A stack-based buffer overflow vulnerability in libtasn1 v4.20.0 allows attackers to execute arbitrary code or cause denial of service by exploiting im...

Jan 7, 2026
CVE-2025-42877
7.5

CVE-2025-42877 is a memory corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server that allows un...

Dec 9, 2025
CVE-2025-13654
7.5

A stack buffer overflow vulnerability in duc's buffer_get function allows out-of-bounds memory reads due to an underflow condition. This could potenti...

Dec 5, 2025
CVE-2024-45539
7.5

An out-of-bounds write vulnerability in CGI components of Synology DiskStation Manager (DSM) and Unified Controller (DSMUC) allows remote attackers to...

Dec 4, 2025
CVE-2025-42940
7.5

CVE-2025-42940 is a memory corruption vulnerability in SAP CommonCryptoLib that occurs when parsing manipulated ASN.1 data during pre-authentication. ...

Nov 11, 2025
CVE-2025-20725
7.5

This vulnerability in the IMS service allows remote privilege escalation through an out-of-bounds write when a user equipment (UE) connects to a rogue...

Nov 4, 2025
CVE-2025-60341
7.5

This vulnerability is a stack buffer overflow in Tenda AC6 V2.0 routers through the fast_setting_wifi_set function's ssid parameter. Attackers can exp...

Oct 22, 2025
CVE-2025-60337
7.5

A buffer overflow vulnerability exists in Tenda AC6 V2.0 routers in the SetSpeedWan function's speed_dir parameter. Attackers can exploit this by send...

Oct 22, 2025
CVE-2025-58096
7.5

A configuration-specific vulnerability in F5 BIG-IP systems where setting the tm.tcpudptxchecksum database variable to 'Software-only' (non-default) c...

Oct 15, 2025
CVE-2025-55036
7.5

A memory corruption vulnerability in BIG-IP SSL Orchestrator's explicit forward proxy when proxy connect is enabled allows attackers to potentially ex...

Oct 15, 2025
CVE-2025-54479
7.5

This vulnerability in F5 BIG-IP systems allows remote attackers to cause denial of service by sending specially crafted requests to virtual servers wi...

Oct 15, 2025
CVE-2025-60663
7.5

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code or cause denial of serv...

Oct 2, 2025
CVE-2025-60660
7.5

A stack overflow vulnerability in Tenda AC18 routers allows attackers to execute arbitrary code by sending specially crafted requests to the vulnerabl...

Oct 2, 2025
CVE-2025-60662
7.5

A stack overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially...

Oct 2, 2025
CVE-2024-48014
7.5

Dell BSAFE Micro Edition Suite versions before 5.0.2.3 contain an out-of-bounds write vulnerability. An unauthenticated remote attacker could exploit ...

Sep 25, 2025
CVE-2025-55599
7.5

A buffer overflow vulnerability in D-Link DIR-619L routers allows attackers to execute arbitrary code by sending specially crafted input to the formWl...

Aug 22, 2025
CVE-2025-41649
7.5

An unauthenticated remote attacker can exploit insufficient input validation to write data beyond buffer bounds, potentially causing denial-of-service...

May 27, 2025
CVE-2025-26785
7.5

A memory corruption vulnerability in Samsung Exynos processors allows attackers to write data beyond allocated buffer boundaries due to missing length...

May 14, 2025
CVE-2025-41431
7.5

This vulnerability allows undisclosed requests to cause the Traffic Management Microkernel (TMM) to terminate on standby BIG-IP systems when connectio...

May 7, 2025
CVE-2025-32402
7.5

An out-of-bounds write vulnerability in RT-Labs P-Net library versions 1.0.1 or earlier allows attackers to crash IO devices by sending malicious RPC ...

May 7, 2025
CVE-2025-32405
7.5

An out-of-bounds write vulnerability in RT-Labs P-Net library allows attackers to crash IO devices by sending malicious RPC packets. This affects indu...

May 7, 2025
CVE-2025-25372
7.5

CVE-2025-25372 is a memory corruption vulnerability in NASA cFS Aquila's Memory Management Module that allows remote attackers to cause a segmentation...

Mar 25, 2025
CVE-2025-27598
7.5

An out-of-bounds write vulnerability in ImageSharp's GIF decoder allows attackers to cause denial of service by crashing applications processing speci...

Mar 6, 2025
CVE-2025-25901
7.5

A buffer overflow vulnerability in TP-Link TL-WR841ND V11 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted packe...

Feb 13, 2025
CVE-2025-25897
7.5

A buffer overflow vulnerability in TP-Link TL-WR841ND V11 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted packe...

Feb 13, 2025
CVE-2025-25898
7.5

A buffer overflow vulnerability in TP-Link TL-WR841ND V11 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted packe...

Feb 13, 2025
CVE-2025-24326
7.5

A memory exhaustion vulnerability in F5 BIG-IP Advanced WAF/ASM when the Behavioral DoS TLS Signatures feature is enabled. Attackers can send speciall...

Feb 5, 2025
CVE-2024-7695
7.5

An out-of-bounds write vulnerability in multiple Moxa industrial switches allows attackers to write data beyond allocated buffer boundaries due to ins...

Jan 29, 2025
CVE-2024-24423
7.5

A buffer overflow vulnerability in Magma's decode_esm_message_container function allows attackers to cause Denial of Service via crafted NAS packets. ...

Jan 21, 2025
CVE-2023-37032
7.5

A stack-based buffer overflow vulnerability in Magma's Mobile Management Entity (MME) allows remote attackers to crash the service by sending speciall...

Jan 21, 2025
CVE-2024-13168
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13170
7.5

This vulnerability allows remote unauthenticated attackers to cause denial of service through an out-of-bounds write in Ivanti EPM. It affects Ivanti ...

Jan 14, 2025
CVE-2024-13165
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13166
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13167
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,381 CVEs classified as CWE-787, with 844 rated critical and 2,324 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free