CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,458
Total CVEs
860
Critical
2,382
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 433
2 Adobe 293
3 Apple 247
4 Linux 234
5 Debian 199
6 Tenda 189
7 Fedoraproject 142
8 Microsoft 99
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,458)

CVE-2023-32888
7.5

This vulnerability in MediaTek's Modem IMS Call UA allows remote attackers to cause denial of service via an out-of-bounds write due to missing bounds...

Jan 2, 2024
CVE-2021-46901
7.5

CVE-2021-46901 is a stack-based buffer overflow vulnerability in CETIC-6LBR's HTTP server component that allows remote attackers to execute arbitrary ...

Dec 31, 2023
CVE-2023-51080
7.5

A stack overflow vulnerability in hutool-core's NumberUtil.toBigDecimal method allows attackers to cause denial of service by providing specially craf...

Dec 27, 2023
CVE-2023-46803
7.5

This vulnerability allows attackers to send specially crafted data packets to the Mobile Device Server, causing memory corruption that can lead to Den...

Dec 19, 2023
CVE-2023-49355
7.5

This vulnerability in jq's decNumber library allows a one-byte out-of-bounds write when processing specially crafted numeric input strings. Attackers ...

Dec 11, 2023
CVE-2023-48963
7.5

CVE-2023-48963 is a buffer overflow vulnerability in Tenda i6 routers that allows remote attackers to execute arbitrary code or cause denial of servic...

Nov 30, 2023
CVE-2023-48945
7.5

A stack overflow vulnerability in OpenLink Virtuoso OpenSource v7.2.11 allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

Nov 29, 2023
CVE-2023-49047
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by exploiting a stack overflow in the device name setting...

Nov 27, 2023
CVE-2022-44010
7.5

This vulnerability allows unauthenticated attackers to send crafted HTTP requests to ClickHouse's HTTP endpoint (port 8123), causing a heap-based buff...

Nov 23, 2023
CVE-2023-48105
7.5

A heap overflow vulnerability in Bytecode Alliance's wasm-micro-runtime version 1.2.3 allows remote attackers to cause denial of service by exploiting...

Nov 22, 2023
CVE-2023-47016
7.5

CVE-2023-47016 is an out-of-bounds read vulnerability in radare2's binary object handling that can cause application crashes. Attackers could potentia...

Nov 22, 2023
CVE-2023-48109
7.5

This vulnerability in Tenda AX1803 routers allows attackers to trigger a heap overflow via the deviceId parameter in the saveParentControlInfo functio...

Nov 20, 2023
CVE-2023-48111
7.5

This vulnerability in Tenda AX1803 routers allows attackers to trigger a stack overflow via the time parameter in the saveParentControlInfo function, ...

Nov 20, 2023
CVE-2023-46760
7.5

This CVE describes an out-of-bounds write vulnerability in a kernel driver module that could allow attackers to cause process exceptions or potentiall...

Nov 8, 2023
CVE-2023-46770
7.5

This CVE describes an out-of-bounds vulnerability in the sensor module of Huawei/HarmonyOS devices that could allow attackers to cause mistouch preven...

Nov 8, 2023
CVE-2023-44197
7.5

An out-of-bounds write vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated network attackers to cause denial of service by...

Oct 13, 2023
CVE-2023-43862
7.5

This vulnerability in D-Link DIR-619L B1 routers allows attackers to execute arbitrary code via a buffer overflow in the formLanguageChange function. ...

Sep 28, 2023
CVE-2023-43864
7.5

This vulnerability in D-Link DIR-619L routers allows remote attackers to execute arbitrary code via a buffer overflow in the formSetWAN_Wizard55 funct...

Sep 28, 2023
CVE-2023-43866
7.5

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-619L B1 routers via a buffer overflow in the formSetWAN_Wizard7 fun...

Sep 28, 2023
CVE-2023-43868
7.5

This buffer overflow vulnerability in D-Link DIR-619L B1 routers allows attackers to execute arbitrary code or cause denial of service by sending spec...

Sep 28, 2023
CVE-2023-43860
7.5

This vulnerability in D-Link DIR-619L B1 routers allows remote attackers to execute arbitrary code via a buffer overflow in the formSetWanNonLogin fun...

Sep 28, 2023
CVE-2023-41307
7.5

CVE-2023-41307 is a memory overwriting vulnerability in Huawei/HarmonyOS security modules that could allow attackers to corrupt memory and cause syste...

Sep 27, 2023
CVE-2023-40018
7.5

FreeSWITCH versions before 1.10.10 contain an out-of-bounds write vulnerability in ICE candidate handling. Remote attackers can trigger memory corrupt...

Sep 15, 2023
CVE-2020-19323
7.5

This vulnerability is a heap buffer overflow in the mini_upnpd service on D-Link DIR-619L routers. Remote attackers can exploit it without authenticat...

Sep 11, 2023
CVE-2023-36184
7.5

CVE-2023-36184 is a stack overflow vulnerability in Mysten Labs Sui blockchain v1.2.0 that can be triggered via the /spec/openrpc.json endpoint. This ...

Sep 8, 2023
CVE-2023-40915
7.5

This vulnerability in Tenda AX3 routers allows attackers to trigger a stack buffer overflow via the ssid parameter in the form_fast_setting_wifi_set f...

Aug 25, 2023
CVE-2022-48570
7.5

CVE-2022-48570 is a timing side channel vulnerability in Crypto++ library's ECDSA signature generation that could allow attackers to infer private key...

Aug 22, 2023
CVE-2022-43357
7.5

A stack overflow vulnerability in libsass's CompoundSelector::has_real_parent_ref function allows attackers to cause denial of service by crashing the...

Aug 22, 2023
CVE-2022-34038
7.5

This vulnerability in etcd v3.5.4 allows remote attackers to cause a denial of service by exploiting a flaw in the PageWriter.write function. Attacker...

Aug 22, 2023
CVE-2022-28068
7.5

CVE-2022-28068 is a heap buffer overflow vulnerability in the r_sleb128 function of radare2, a popular reverse engineering framework. Attackers can ex...

Aug 22, 2023
CVE-2022-28072
7.5

A heap buffer overflow vulnerability in the r_read_le32 function of radare2 versions 5.4.2 and 5.4.0 allows attackers to execute arbitrary code or cau...

Aug 22, 2023
CVE-2021-46174
7.5

CVE-2021-46174 is a heap-based buffer overflow vulnerability in the bfd_getl32 function of Binutils objdump version 2.37. This vulnerability allows at...

Aug 22, 2023
CVE-2021-34193
7.5

CVE-2021-34193 is a stack overflow vulnerability in OpenSC smart card middleware that allows remote attackers to execute arbitrary code or cause denia...

Aug 22, 2023
CVE-2020-22218
7.5

This vulnerability in libssh2 1.10.0 allows attackers to access out-of-bounds memory through the _libssh2_packet_add function. This could lead to info...

Aug 22, 2023
CVE-2023-39786
7.5

This CVE describes a stack overflow vulnerability in Tenda AC8V4 routers via the time parameter in the sscanf function. Attackers can exploit this to ...

Aug 21, 2023
CVE-2023-39784
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers via a stack overflow in the save_virtualser_data function....

Aug 21, 2023
CVE-2023-40711
7.5

This vulnerability in Veilid allows remote attackers to send specially crafted packets that cause excessive memory consumption during decompression, l...

Aug 20, 2023
CVE-2023-39827
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda A18 routers by exploiting a stack overflow in the MAC filter rule manage...

Aug 14, 2023
CVE-2023-39829
7.5

This vulnerability is a stack overflow in Tenda A18 routers that allows remote attackers to execute arbitrary code by sending a specially crafted requ...

Aug 14, 2023
CVE-2023-30699
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected Samsung devices through an out-of-bounds write in the libsimba librar...

Aug 10, 2023
CVE-2023-4050
7.5

This vulnerability allows an attacker to cause a stack buffer overflow by sending untrusted input without proper size validation. If exploited, it cou...

Aug 1, 2023
CVE-2023-34934
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) on H3C Magic B1ST routers by sending a specially crafted POST request that trig...

Jun 28, 2023
CVE-2023-34936
7.5

A stack overflow vulnerability in the UpdateMacClone function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) vi...

Jun 28, 2023
CVE-2023-34928
7.5

A stack overflow vulnerability in the Edit_BasicSSID function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) vi...

Jun 28, 2023
CVE-2023-34930
7.5

A stack overflow vulnerability in the EditMacList function of H3C Magic B1STV100R012 routers allows attackers to cause Denial of Service (DoS) via cra...

Jun 28, 2023
CVE-2023-34932
7.5

A stack overflow vulnerability in the UpdateWanMode function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) via...

Jun 28, 2023
CVE-2023-34924
7.5

H3C Magic B1STW B1STV100R012 routers contain a stack overflow vulnerability in the SetAPInfoById function that allows attackers to cause Denial of Ser...

Jun 26, 2023
CVE-2023-32397
7.5

This vulnerability allows malicious apps to bypass file system protection mechanisms and modify restricted areas of the file system on Apple devices. ...

Jun 23, 2023
CVE-2022-48486
7.5

This vulnerability involves configuration defects in the secure OS module of certain Huawei devices, allowing attackers to cause denial of service con...

Jun 19, 2023
CVE-2023-32209
7.5

CVE-2023-32209 is a memory corruption vulnerability in Firefox where a maliciously crafted favicon could cause an out-of-memory crash. This affects Fi...

Jun 19, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,458 CVEs classified as CWE-787, with 860 rated critical and 2,382 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free