CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,701
Total CVEs
611
Critical
1,877
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 309
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 59

All Out-of-bounds Write CVEs (2,701)

CVE-2023-39751
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WR941ND V6 routers via a buffer overflow in the ping functionality....

Aug 21, 2023
CVE-2023-30187
9.8

CVE-2023-30187 is a critical out-of-bounds memory access vulnerability in ONLYOFFICE DocumentServer that allows remote attackers to execute arbitrary ...

Aug 14, 2023
CVE-2023-32560
9.8

This vulnerability in Wavelink Avalanche Manager allows an attacker to send a specially crafted message, potentially leading to service disruption or ...

Aug 10, 2023
CVE-2023-40041
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK T10_v2 routers by exploiting a stack-based buffer overflow in the WPS...

Aug 8, 2023
CVE-2023-38932
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the SafeEmailFilter function. A...

Aug 7, 2023
CVE-2023-38934
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the formSetDeviceName function....

Aug 7, 2023
CVE-2023-38936
9.8

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attacke...

Aug 7, 2023
CVE-2023-38938
9.8

This vulnerability is a stack overflow in Tenda routers' web interface that allows remote code execution. Attackers can exploit it by sending speciall...

Aug 7, 2023
CVE-2023-38940
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the WiFi configuration function...

Aug 7, 2023
CVE-2023-38930
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the addWifiMacFilter function. ...

Aug 7, 2023
CVE-2023-4056
9.8

This CVE describes memory safety bugs, including potential memory corruption, in multiple Mozilla products that could allow an attacker to execute arb...

Aug 1, 2023
CVE-2023-4058
9.8

CVE-2023-4058 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulne...

Aug 1, 2023
CVE-2023-31710
9.8

This CVE describes a buffer overflow vulnerability in TP-Link Archer AX21 routers that could allow remote code execution. Attackers can exploit this t...

Aug 1, 2023
CVE-2023-38604
9.8

This is a critical kernel privilege escalation vulnerability in Apple operating systems. An out-of-bounds write allows malicious apps to execute arbit...

Jul 28, 2023
CVE-2023-38632
9.8

CVE-2023-38632 is a critical stack-based buffer overflow vulnerability in async-sockets-cpp library versions through 0.3.1. Attackers can exploit this...

Jul 21, 2023
CVE-2021-34123
9.8

CVE-2021-34123 is a critical stack buffer overflow vulnerability in atasm v1.09's aprintf() function that allows remote code execution when processing...

Jul 18, 2023
CVE-2023-37791
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-619L routers via a stack overflow in the login form. Attackers can ...

Jul 17, 2023
CVE-2023-37715
9.8

This vulnerability is a stack overflow in Tenda F1202 and FH1202 routers that allows remote code execution. Attackers can exploit it by sending specia...

Jul 14, 2023
CVE-2023-37717
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function...

Jul 14, 2023
CVE-2023-37719
9.8

CVE-2023-37719 is a critical stack overflow vulnerability in Tenda F1202 and FH1202 routers that allows remote code execution. Attackers can exploit t...

Jul 14, 2023
CVE-2023-37722
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromSafeUrlFilter function....

Jul 14, 2023
CVE-2023-23585
9.8

CVE-2023-23585 is a critical heap overflow vulnerability in Honeywell Experion servers that allows remote attackers to cause denial of service (DoS) b...

Jul 13, 2023
CVE-2023-21250
9.8

This is a critical Bluetooth stack vulnerability in Android's GATT implementation that allows remote code execution without user interaction. Attacker...

Jul 13, 2023
CVE-2023-37701
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH1203 routers by exploiting a stack overflow in the addWifiMacFilter fu...

Jul 10, 2023
CVE-2023-37703
9.8

This vulnerability in Tenda FH1203 routers allows remote attackers to execute arbitrary code via a stack overflow in the speed_dir parameter. Attacker...

Jul 10, 2023
CVE-2023-37705
9.8

This vulnerability in Tenda FH1203 routers allows remote attackers to execute arbitrary code via a stack overflow in the fromAddressNat function. Atta...

Jul 10, 2023
CVE-2023-37707
9.8

CVE-2023-37707 is a critical stack overflow vulnerability in Tenda FH1203 routers that allows remote attackers to execute arbitrary code or cause deni...

Jul 10, 2023
CVE-2023-37711
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the deviceId parameter. Attacke...

Jul 10, 2023
CVE-2020-22336
9.8

CVE-2020-22336 is a stack buffer overflow vulnerability in pdfcrack's MD5 function that allows attackers to execute arbitrary code. This affects pdfcr...

Jul 6, 2023
CVE-2023-21066
9.8

This critical Android kernel vulnerability allows remote attackers to execute arbitrary code without user interaction or special privileges. It affect...

Jun 28, 2023
CVE-2023-36660
9.8

CVE-2023-36660 is a memory corruption vulnerability in the OCB (Offset Codebook) mode implementation in libnettle cryptographic library versions 3.9. ...

Jun 25, 2023
CVE-2023-34416
9.8

CVE-2023-34416 is a critical memory safety vulnerability affecting Mozilla Firefox, Firefox ESR, and Thunderbird. It involves memory corruption bugs t...

Jun 19, 2023
CVE-2023-29531
9.8

This vulnerability allows an attacker to trigger an out-of-bounds memory access via WebGL APIs in Firefox or Thunderbird on macOS, potentially leading...

Jun 19, 2023
CVE-2023-32216
9.8

CVE-2023-32216 is a critical memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The ...

Jun 19, 2023
CVE-2014-125106
9.8

This CVE describes a size_t overflow vulnerability in Nanopb's pb_dec_bytes and pb_dec_string functions, allowing attackers to cause buffer overflows ...

Jun 17, 2023
CVE-2023-29562
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WPA7510 devices via a stack overflow in the operation parameter at ...

Jun 13, 2023
CVE-2022-28550
9.8

CVE-2022-28550 is a critical buffer overflow vulnerability in jhead image metadata tool that allows attackers to execute arbitrary code or crash the a...

Jun 13, 2023
CVE-2023-34364
9.8

This vulnerability allows remote code execution via buffer overflow in Progress DataDirect Connect for ODBC Oracle Wire Protocol driver. Attackers can...

Jun 9, 2023
CVE-2023-34566
9.8

This vulnerability is a stack overflow in Tenda AC10 routers that allows remote attackers to execute arbitrary code by sending specially crafted reque...

Jun 8, 2023
CVE-2023-33669
9.8

CVE-2023-33669 is a critical stack overflow vulnerability in Tenda AC8 routers that allows remote code execution via the timeZone parameter. Attackers...

Jun 2, 2023
CVE-2023-33671
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8 routers via a stack overflow in the saveParentControlInfo function. ...

Jun 2, 2023
CVE-2023-33673
9.8

This vulnerability is a stack overflow in Tenda AC8 routers via the firewallEn parameter in the formSetFirewallCfg function. It allows remote attacker...

Jun 2, 2023
CVE-2023-33476
9.8

CVE-2023-33476 is a critical buffer overflow vulnerability in ReadyMedia (MiniDLNA) that allows remote attackers to execute arbitrary code or cause de...

Jun 2, 2023
CVE-2023-23306
9.8

This vulnerability allows a malicious Connect IQ application to exploit type confusion in the Toybox.Ant.BurstPayload.add API method, leading to out-o...

May 23, 2023
CVE-2023-23556
9.8

A memory corruption vulnerability in Hermes JavaScript engine allows arbitrary code execution when converting BigInt to Number values. This affects Re...

May 18, 2023
CVE-2023-28753
9.8

CVE-2023-28753 is an integer overflow vulnerability in netconsd's parse_packet function that allows heap memory corruption with attacker-controlled da...

May 18, 2023
CVE-2023-27217
9.8

A stack-based buffer overflow vulnerability in Belkin Smart Outlet V2's ChangeFriendlyName() function allows attackers to cause Denial of Service via ...

May 18, 2023
CVE-2023-29961
9.8

CVE-2023-29961 is a critical stack overflow vulnerability in D-Link DIR-605L routers that allows remote attackers to execute arbitrary code by sending...

May 16, 2023
CVE-2023-20520
9.8

This vulnerability in AMD ASP Bootloader allows attackers to corrupt return addresses via stack-based buffer overflows, potentially leading to arbitra...

May 9, 2023
CVE-2023-27953
9.8

This is a critical memory corruption vulnerability in macOS kernel that allows remote attackers to cause system crashes or corrupt kernel memory. It a...

May 8, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,701 CVEs classified as CWE-787, with 611 rated critical and 1,877 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free