CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,451
Total CVEs
859
Critical
2,376
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 432
2 Adobe 292
3 Apple 247
4 Linux 232
5 Debian 197
6 Tenda 189
7 Fedoraproject 141
8 Microsoft 99
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,451)

CVE-2025-24326
7.5

A memory exhaustion vulnerability in F5 BIG-IP Advanced WAF/ASM when the Behavioral DoS TLS Signatures feature is enabled. Attackers can send speciall...

Feb 5, 2025
CVE-2024-7695
7.5

An out-of-bounds write vulnerability in multiple Moxa industrial switches allows attackers to write data beyond allocated buffer boundaries due to ins...

Jan 29, 2025
CVE-2024-24423
7.5

A buffer overflow vulnerability in Magma's decode_esm_message_container function allows attackers to cause Denial of Service via crafted NAS packets. ...

Jan 21, 2025
CVE-2023-37032
7.5

A stack-based buffer overflow vulnerability in Magma's Mobile Management Entity (MME) allows remote attackers to crash the service by sending speciall...

Jan 21, 2025
CVE-2024-13168
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13170
7.5

This vulnerability allows remote unauthenticated attackers to cause denial of service through an out-of-bounds write in Ivanti EPM. It affects Ivanti ...

Jan 14, 2025
CVE-2024-13165
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13166
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-13167
7.5

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing t...

Jan 14, 2025
CVE-2024-47541
7.5

This CVE describes an out-of-bounds write vulnerability in GStreamer's SSA subtitle parser. Attackers can exploit this by crafting malicious media fil...

Dec 12, 2024
CVE-2024-34669
7.5

CVE-2024-34669 is an out-of-bounds write vulnerability in librtppayload.so's h.263+ format parser that allows remote attackers to execute arbitrary co...

Oct 8, 2024
CVE-2024-34665
7.5

This vulnerability allows remote attackers to execute arbitrary code with system privileges by exploiting an out-of-bounds write in the H.264 parsing ...

Oct 8, 2024
CVE-2024-34667
7.5

This vulnerability allows remote attackers to execute arbitrary code with system privileges by exploiting an out-of-bounds write in the H.265 video fo...

Oct 8, 2024
CVE-2024-44375
7.5

This CVE describes a stack overflow vulnerability in the dbsrv_asp function of D-Link DI-8100 routers running firmware version 16.07.26A1. Attackers c...

Sep 9, 2024
CVE-2024-42980
7.5

This CVE describes a stack overflow vulnerability in Tenda FH1206 routers that allows attackers to cause Denial of Service (DoS) through specially cra...

Aug 15, 2024
CVE-2024-42982
7.5

This vulnerability in Tenda FH1206 routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request that trigge...

Aug 15, 2024
CVE-2024-42984
7.5

Tenda FH1206 routers running firmware v02.03.01.35 contain a stack overflow vulnerability in the fromP2pListFilter function via the page parameter. At...

Aug 15, 2024
CVE-2024-42986
7.5

This vulnerability in Tenda FH1206 routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request that trigge...

Aug 15, 2024
CVE-2024-42968
7.5

This vulnerability in Tenda FH1206 routers allows attackers to trigger a stack overflow via the Go parameter in the fromSafeUrlFilter function through...

Aug 15, 2024
CVE-2024-42973
7.5

This vulnerability in Tenda FH1206 routers allows attackers to trigger a stack overflow via a crafted POST request to the fromSetlpBind function, caus...

Aug 15, 2024
CVE-2024-42976
7.5

Tenda FH1206 routers running firmware v02.03.01.35 contain a stack overflow vulnerability in the fromSafeClientFilter function's page parameter. Attac...

Aug 15, 2024
CVE-2024-42945
7.5

Tenda FH1201 routers running firmware v1.2.0.14 (408) contain a stack overflow vulnerability in the fromAddressNat function's page parameter. Attacker...

Aug 15, 2024
CVE-2024-42949
7.5

This vulnerability in Tenda FH1201 routers allows attackers to trigger a stack overflow via a crafted POST request to the qos parameter, leading to De...

Aug 15, 2024
CVE-2024-42951
7.5

CVE-2024-42951 is a stack overflow vulnerability in Tenda FH1201 routers that allows attackers to cause Denial of Service (DoS) by sending specially c...

Aug 15, 2024
CVE-2024-42953
7.5

Tenda FH1201 routers running firmware v1.2.0.14 (408) contain a stack overflow vulnerability in the fromWizardHandle function's PPW parameter. Attacke...

Aug 15, 2024
CVE-2024-42955
7.5

CVE-2024-42955 is a stack overflow vulnerability in Tenda FH1201 routers that allows attackers to cause Denial of Service (DoS) by sending specially c...

Aug 15, 2024
CVE-2024-42941
7.5

This vulnerability in Tenda FH1201 routers allows attackers to trigger a stack overflow via a crafted POST request to the wanmode parameter. Exploitat...

Aug 15, 2024
CVE-2024-42943
7.5

This vulnerability in Tenda FH1201 routers allows attackers to trigger a stack overflow by sending a specially crafted POST request to the PPPOEPasswo...

Aug 15, 2024
CVE-2022-23815
7.5

This vulnerability allows attackers to write outside the bounds of APCB firmware memory, potentially corrupting system data structures and enabling ar...

Aug 13, 2024
CVE-2024-41463
7.5

CVE-2024-41463 is a stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code or cause ...

Jul 24, 2024
CVE-2024-41465
7.5

CVE-2024-41465 is a stack-based buffer overflow vulnerability in Tenda FH1201 routers that allows remote attackers to execute arbitrary code by sendin...

Jul 24, 2024
CVE-2024-41131
7.5

An out-of-bounds write vulnerability in ImageSharp's GIF decoder allows attackers to cause denial of service by crashing applications processing speci...

Jul 22, 2024
CVE-2024-21175
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server's integrity. Attac...

Jul 16, 2024
CVE-2024-20376
7.5

An unauthenticated remote attacker can send a crafted request to the web-based management interface of vulnerable Cisco IP Phone firmware, causing the...

May 1, 2024
CVE-2023-52386
7.5

CVE-2023-52386 is an out-of-bounds write vulnerability in the RSMC module affecting Huawei devices running HarmonyOS. Successful exploitation could ca...

Apr 8, 2024
CVE-2024-21661
7.5

CVE-2024-21661 is a critical Denial of Service vulnerability in Argo CD that allows unauthenticated attackers to crash the application by exploiting u...

Mar 18, 2024
CVE-2024-27570
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) on LBT T300-T390 routers by exploiting a stack overflow in the ApCliSsid parame...

Mar 1, 2024
CVE-2024-25200
7.5

Espruino 2v20 contains a stack overflow vulnerability in its JavaScript parser that can be triggered via specially crafted code. This allows attackers...

Feb 7, 2024
CVE-2024-21780
7.5

A stack-based buffer overflow vulnerability in HOME SPOT CUBE2 routers allows attackers to cause denial of service by sending specially crafted comman...

Feb 2, 2024
CVE-2023-52110
7.5

This CVE describes an out-of-bounds access vulnerability in Huawei sensor modules that could allow attackers to crash affected systems, affecting avai...

Jan 16, 2024
CVE-2023-49427
7.5

A buffer overflow vulnerability in Tenda AX12 routers allows remote attackers to cause denial of service by sending specially crafted requests to the ...

Jan 10, 2024
CVE-2022-2081
7.5

A stack overflow vulnerability in the HCI Modbus TCP function of Hitachi Energy RTU500 devices allows attackers to cause denial of service by sending ...

Jan 4, 2024
CVE-2023-32886
7.5

This vulnerability allows remote attackers to cause denial of service on affected devices by exploiting an out-of-bounds write in the Modem IMS SMS UA...

Jan 2, 2024
CVE-2023-32888
7.5

This vulnerability in MediaTek's Modem IMS Call UA allows remote attackers to cause denial of service via an out-of-bounds write due to missing bounds...

Jan 2, 2024
CVE-2021-46901
7.5

CVE-2021-46901 is a stack-based buffer overflow vulnerability in CETIC-6LBR's HTTP server component that allows remote attackers to execute arbitrary ...

Dec 31, 2023
CVE-2023-51080
7.5

A stack overflow vulnerability in hutool-core's NumberUtil.toBigDecimal method allows attackers to cause denial of service by providing specially craf...

Dec 27, 2023
CVE-2023-46803
7.5

This vulnerability allows attackers to send specially crafted data packets to the Mobile Device Server, causing memory corruption that can lead to Den...

Dec 19, 2023
CVE-2023-49355
7.5

This vulnerability in jq's decNumber library allows a one-byte out-of-bounds write when processing specially crafted numeric input strings. Attackers ...

Dec 11, 2023
CVE-2023-48963
7.5

CVE-2023-48963 is a buffer overflow vulnerability in Tenda i6 routers that allows remote attackers to execute arbitrary code or cause denial of servic...

Nov 30, 2023
CVE-2023-48945
7.5

A stack overflow vulnerability in OpenLink Virtuoso OpenSource v7.2.11 allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

Nov 29, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,451 CVEs classified as CWE-787, with 859 rated critical and 2,376 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free