CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,468
Total CVEs
861
Critical
2,391
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 433
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 200
6 Tenda 189
7 Fedoraproject 142
8 Microsoft 99
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,468)

CVE-2023-34934
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) on H3C Magic B1ST routers by sending a specially crafted POST request that trig...

Jun 28, 2023
CVE-2023-34936
7.5

A stack overflow vulnerability in the UpdateMacClone function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) vi...

Jun 28, 2023
CVE-2023-34928
7.5

A stack overflow vulnerability in the Edit_BasicSSID function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) vi...

Jun 28, 2023
CVE-2023-34930
7.5

A stack overflow vulnerability in the EditMacList function of H3C Magic B1STV100R012 routers allows attackers to cause Denial of Service (DoS) via cra...

Jun 28, 2023
CVE-2023-34932
7.5

A stack overflow vulnerability in the UpdateWanMode function of H3C Magic B1STV100R012 routers allows attackers to cause a Denial of Service (DoS) via...

Jun 28, 2023
CVE-2023-34924
7.5

H3C Magic B1STW B1STV100R012 routers contain a stack overflow vulnerability in the SetAPInfoById function that allows attackers to cause Denial of Ser...

Jun 26, 2023
CVE-2023-32397
7.5

This vulnerability allows malicious apps to bypass file system protection mechanisms and modify restricted areas of the file system on Apple devices. ...

Jun 23, 2023
CVE-2022-48486
7.5

This vulnerability involves configuration defects in the secure OS module of certain Huawei devices, allowing attackers to cause denial of service con...

Jun 19, 2023
CVE-2023-32209
7.5

CVE-2023-32209 is a memory corruption vulnerability in Firefox where a maliciously crafted favicon could cause an out-of-memory crash. This affects Fi...

Jun 19, 2023
CVE-2023-34613
7.5

CVE-2023-34613 is a vulnerability in sojo library versions through 1.1.1 that allows attackers to cause denial of service or other impacts by sending ...

Jun 14, 2023
CVE-2023-34615
7.5

CVE-2023-34615 is a vulnerability in JSONUtil library versions through 5.0 that allows attackers to cause denial of service or other impacts by exploi...

Jun 14, 2023
CVE-2023-34617
7.5

CVE-2023-34617 is a vulnerability in genson library versions through 1.6 where attackers can cause denial of service or other impacts by providing cra...

Jun 14, 2023
CVE-2023-34623
7.5

This vulnerability in jtidy allows attackers to create denial of service conditions or other unspecified impacts by exploiting cyclic dependencies in ...

Jun 14, 2023
CVE-2023-35110
7.5

CVE-2023-35110 is a vulnerability in jjson library versions through 0.1.7 where attackers can cause denial of service or other impacts by sending JSON...

Jun 14, 2023
CVE-2023-34609
7.5

This vulnerability in flexjson allows attackers to cause denial of service or potentially other impacts by sending crafted objects with cyclic depende...

Jun 14, 2023
CVE-2023-34611
7.5

This vulnerability in mjson library versions through 1.4.1 allows attackers to cause denial of service or potentially other impacts by sending crafted...

Jun 14, 2023
CVE-2023-33658
7.5

A heap buffer overflow vulnerability in NanoMQ 0.17.2 allows attackers to trigger denial of service by exploiting the nni_msg_get_pub_pid() function. ...

Jun 8, 2023
CVE-2023-33659
7.5

A heap buffer overflow vulnerability in NanoMQ 0.17.2 allows attackers to trigger denial of service by exploiting the nmq_subinfo_decode() function. T...

Jun 6, 2023
CVE-2022-30114
7.5

A heap-based buffer overflow vulnerability in Fastweb FASTGate routers allows remote attackers to cause denial-of-service by rebooting the device thro...

May 19, 2023
CVE-2023-31922
7.5

CVE-2023-31922 is a stack overflow vulnerability in QuickJS's js_proxy_isArray function that can lead to denial of service or potential remote code ex...

May 12, 2023
CVE-2023-31146
7.5

This vulnerability in Vyper smart contract language allows out-of-bounds array access during dynamic array assignments, potentially causing data corru...

May 11, 2023
CVE-2021-46763
7.5

This vulnerability allows a privileged attacker to write beyond intended memory bounds in AMD's System Management Unit (SMU), potentially compromising...

May 9, 2023
CVE-2023-32111
7.5

This vulnerability in SAP PowerDesigner Proxy allows remote attackers to crash the proxy server by sending a specially crafted request, causing memory...

May 9, 2023
CVE-2023-29994
7.5

A heap overflow vulnerability in NanoMQ's read_byte function allows attackers to write beyond allocated memory boundaries. This affects all systems ru...

May 4, 2023
CVE-2023-22640
7.5

This CVE describes an out-of-bounds write vulnerability in multiple Fortinet products that allows authenticated attackers to execute arbitrary code or...

May 3, 2023
CVE-2023-26976
7.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by sending a specially crafted request to the WiFi configura...

Apr 4, 2023
CVE-2023-27077
7.5

A stack overflow vulnerability in 360 D901 routers allows remote attackers to trigger a Distributed Denial of Service (DDOS) by sending specially craf...

Mar 23, 2023
CVE-2023-25283
7.5

A stack overflow vulnerability in D-Link DIR-820L routers allows attackers to cause denial of service by sending specially crafted requests to the lan...

Mar 13, 2023
CVE-2021-36493
7.5

A buffer overflow vulnerability in the pdfimages utility of xpdf 4.03 allows attackers to crash the application by providing a specially crafted PDF f...

Feb 3, 2023
CVE-2022-34033
7.5

CVE-2022-34033 is a heap buffer overflow vulnerability in HTMLDoc's write_header function that allows attackers to execute arbitrary code or cause den...

Jul 18, 2022
CVE-2020-14127
7.5

This CVE describes a heap overflow vulnerability in certain Xiaomi phone models that allows remote attackers to cause denial of service. The vulnerabi...

Jul 14, 2022
CVE-2022-34759
7.5

This CVE describes an out-of-bounds write vulnerability in Schneider Electric's X80 advanced RTU and OPC UA Modicon communication modules. Improper pa...

Jul 13, 2022
CVE-2021-33647
7.5

CVE-2021-33647 is an out-of-bounds write vulnerability in MindSpore's Tile operator that occurs during shape inference when non-integer data types are...

Jun 27, 2022
CVE-2022-24893
7.5

A memory corruption vulnerability in ESP-IDF's Bluetooth Mesh SDK allows attackers to trigger memory corruption during device provisioning by manipula...

Jun 25, 2022
CVE-2022-20209
7.5

This vulnerability allows remote attackers to read memory beyond allocated heap buffers in Android's HME component, potentially disclosing sensitive i...

Jun 15, 2022
CVE-2022-29377
7.5

This vulnerability is a stack buffer overflow in the Totolink A3600R router's infostat.cgi component, triggered via the CONTENT_LENGTH parameter. Atta...

May 24, 2022
CVE-2022-29638
7.5

This CVE describes a stack overflow vulnerability in TOTOLINK A3100R routers that allows attackers to cause a Denial of Service (DoS) by sending a spe...

May 18, 2022
CVE-2022-29640
7.5

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

May 18, 2022
CVE-2022-29642
7.5

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

May 18, 2022
CVE-2022-30040
7.5

CVE-2022-30040 is a buffer overflow vulnerability in Tenda AX1803 routers that allows attackers to cause denial of service by sending specially crafte...

May 11, 2022
CVE-2022-28969
7.5

CVE-2022-28969 is a stack overflow vulnerability in Tenda AX1806 routers that allows attackers to cause a Denial of Service (DoS) by sending specially...

May 6, 2022
CVE-2022-28971
7.5

This vulnerability is a stack overflow in Tenda AX1806 routers via the list parameter in the fromSetIpMacBind function. Attackers can exploit this to ...

May 6, 2022
CVE-2022-28973
7.5

A stack overflow vulnerability exists in Tenda AX1806 routers via the wanMTU parameter in the fromAdvSetMacMtuWan function. Attackers can exploit this...

May 6, 2022
CVE-2022-30293
7.5

A heap-based buffer overflow vulnerability in WebKitGTK's TextureMapperLayer component allows memory corruption when processing malicious web content....

May 6, 2022
CVE-2022-27292
7.5

CVE-2022-27292 is a stack overflow vulnerability in D-Link DIR-619 Ax routers that allows attackers to cause Denial of Service (DoS) by sending specia...

Apr 10, 2022
CVE-2022-27294
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers that allows attackers to cause Denial of Service (DoS) by sending specially crafte...

Apr 10, 2022
CVE-2022-27286
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers that allows attackers to cause a Denial of Service (DoS) by sending specially craf...

Apr 10, 2022
CVE-2022-27288
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers version 1.00, specifically in the formSetWanPPTP function. Attackers can exploit i...

Apr 10, 2022
CVE-2022-27290
7.5

CVE-2022-27290 is a stack overflow vulnerability in D-Link DIR-619 Ax routers that allows attackers to cause a Denial of Service (DoS) by sending spec...

Apr 10, 2022
CVE-2022-26952
7.5

CVE-2022-26952 is a buffer overflow vulnerability in Digi Passport firmware that allows unauthenticated remote attackers to execute arbitrary code or ...

Apr 6, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,468 CVEs classified as CWE-787, with 861 rated critical and 2,391 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free