CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,482
Total CVEs
861
Critical
2,405
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 434
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 203
6 Tenda 189
7 Fedoraproject 143
8 Microsoft 99
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,482)

CVE-2022-29640
7.5

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

May 18, 2022
CVE-2022-29642
7.5

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

May 18, 2022
CVE-2022-30040
7.5

CVE-2022-30040 is a buffer overflow vulnerability in Tenda AX1803 routers that allows attackers to cause denial of service by sending specially crafte...

May 11, 2022
CVE-2022-28969
7.5

CVE-2022-28969 is a stack overflow vulnerability in Tenda AX1806 routers that allows attackers to cause a Denial of Service (DoS) by sending specially...

May 6, 2022
CVE-2022-28971
7.5

This vulnerability is a stack overflow in Tenda AX1806 routers via the list parameter in the fromSetIpMacBind function. Attackers can exploit this to ...

May 6, 2022
CVE-2022-28973
7.5

A stack overflow vulnerability exists in Tenda AX1806 routers via the wanMTU parameter in the fromAdvSetMacMtuWan function. Attackers can exploit this...

May 6, 2022
CVE-2022-30293
7.5

A heap-based buffer overflow vulnerability in WebKitGTK's TextureMapperLayer component allows memory corruption when processing malicious web content....

May 6, 2022
CVE-2022-27292
7.5

CVE-2022-27292 is a stack overflow vulnerability in D-Link DIR-619 Ax routers that allows attackers to cause Denial of Service (DoS) by sending specia...

Apr 10, 2022
CVE-2022-27294
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers that allows attackers to cause Denial of Service (DoS) by sending specially crafte...

Apr 10, 2022
CVE-2022-27286
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers that allows attackers to cause a Denial of Service (DoS) by sending specially craf...

Apr 10, 2022
CVE-2022-27288
7.5

This vulnerability is a stack overflow in D-Link DIR-619 Ax routers version 1.00, specifically in the formSetWanPPTP function. Attackers can exploit i...

Apr 10, 2022
CVE-2022-27290
7.5

CVE-2022-27290 is a stack overflow vulnerability in D-Link DIR-619 Ax routers that allows attackers to cause a Denial of Service (DoS) by sending spec...

Apr 10, 2022
CVE-2022-26952
7.5

CVE-2022-26952 is a buffer overflow vulnerability in Digi Passport firmware that allows unauthenticated remote attackers to execute arbitrary code or ...

Apr 6, 2022
CVE-2021-44081
7.5

A buffer overflow vulnerability in open5gs AMF component allows attackers to cause denial of service by sending specially crafted Supi messages with M...

Mar 29, 2022
CVE-2018-25032
7.5

This vulnerability in zlib allows memory corruption during compression (deflating) when processing input with many distant matches. It affects any sof...

Mar 25, 2022
CVE-2022-22651
7.5

This is a kernel memory corruption vulnerability in macOS that allows remote attackers to trigger out-of-bounds writes. Successful exploitation could ...

Mar 18, 2022
CVE-2020-36518
7.5

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, ...

Mar 11, 2022
CVE-2022-25561
7.5

Tenda AX12 routers running firmware v22.03.01.21 contain a stack overflow vulnerability in the sub_42DE00 function. Attackers can exploit this via the...

Mar 10, 2022
CVE-2022-25558
7.5

Tenda AX1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the formSetProvince function. Attackers can exploit this by s...

Mar 10, 2022
CVE-2022-25554
7.5

Tenda AX1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the saveParentControlInfo function. Attackers can exploit thi...

Mar 10, 2022
CVE-2022-25556
7.5

Tenda AX12 routers running firmware v22.03.01.21 contain a stack overflow vulnerability in the sub_42E328 function. Attackers can exploit this via the...

Mar 10, 2022
CVE-2022-25552
7.5

A stack overflow vulnerability in Tenda AX1806 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the ...

Mar 10, 2022
CVE-2022-25550
7.5

A stack overflow vulnerability in Tenda AX1806 routers allows attackers to cause Denial of Service by sending specially crafted deviceName parameters ...

Mar 10, 2022
CVE-2022-25548
7.5

Tenda AX1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the fromSetSysTime function. Attackers can exploit this by se...

Mar 10, 2022
CVE-2022-25546
7.5

Tenda AX1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the formSetSysToolDDNS function. Attackers can exploit this b...

Mar 10, 2022
CVE-2021-46408
7.5

A stack buffer overflow vulnerability exists in Tenda AX12 routers running firmware v22.03.01.21. Attackers can exploit this via the strcpy parameter ...

Mar 10, 2022
CVE-2021-40064
7.5

CVE-2021-40064 is a heap-based buffer overflow vulnerability in Huawei HarmonyOS and EMUI system components. This vulnerability allows attackers to po...

Mar 10, 2022
CVE-2021-45391
7.5

A buffer overflow vulnerability in Tenda AX12 routers allows attackers to cause denial of service by sending specially crafted requests to the httpd s...

Feb 16, 2022
CVE-2022-24169
7.5

CVE-2022-24169 is a stack overflow vulnerability in Tenda G1 and G3 routers that allows attackers to cause a Denial of Service (DoS) by sending specia...

Feb 4, 2022
CVE-2022-24172
7.5

CVE-2022-24172 is a stack overflow vulnerability in Tenda G1 and G3 routers that allows attackers to cause a Denial of Service (DoS) by sending specia...

Feb 4, 2022
CVE-2022-24152
7.5

CVE-2022-24152 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending s...

Feb 4, 2022
CVE-2022-24154
7.5

This vulnerability is a stack overflow in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can send specially crafted rebootTime p...

Feb 4, 2022
CVE-2022-24156
7.5

CVE-2022-24156 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending s...

Feb 4, 2022
CVE-2022-24158
7.5

CVE-2022-24158 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending s...

Feb 4, 2022
CVE-2022-24160
7.5

CVE-2022-24160 is a stack overflow vulnerability in Tenda AX3 routers that allows attackers to cause Denial of Service (DoS) by sending specially craf...

Feb 4, 2022
CVE-2022-24162
7.5

CVE-2022-24162 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending s...

Feb 4, 2022
CVE-2022-24164
7.5

This vulnerability is a stack overflow in Tenda G1 and G3 routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted ...

Feb 4, 2022
CVE-2022-24143
7.5

This CVE describes a stack overflow vulnerability in Tenda AX3 and AX12 routers' form_fast_setting_wifi_set function. Attackers can exploit it by send...

Feb 4, 2022
CVE-2022-24146
7.5

Tenda AX3 routers running firmware version 16.03.12.10_CN contain a stack overflow vulnerability in the formSetQosBand function. Attackers can exploit...

Feb 4, 2022
CVE-2021-45989
7.5

This vulnerability is a stack overflow in Tenda G1 and G3 routers that allows attackers to cause a Denial of Service (DoS) by sending specially crafte...

Feb 4, 2022
CVE-2021-45992
7.5

This CVE describes a stack overflow vulnerability in Tenda G1 and G3 routers that allows attackers to cause a Denial of Service (DoS) by sending speci...

Feb 4, 2022
CVE-2021-45994
7.5

This CVE describes a stack overflow vulnerability in Tenda G1 and G3 routers that allows attackers to cause a Denial of Service (DoS) by exploiting th...

Feb 4, 2022
CVE-2021-45996
7.5

This CVE describes a stack overflow vulnerability in Tenda G1 and G3 routers that allows attackers to cause Denial of Service (DoS) by sending special...

Feb 4, 2022
CVE-2021-43522
7.5

This vulnerability in Insyde InsydeH2O UEFI firmware allows attackers to write predictable data to SMRAM (System Management RAM) through a memory corr...

Feb 3, 2022
CVE-2020-14107
7.5

This vulnerability is a stack overflow in the HTTP server of Cast that can be exploited via LAN to cause application crashes. It affects Cast devices ...

Jan 18, 2022
CVE-2021-40014
7.5

CVE-2021-40014 is a heap overflow vulnerability in the bone voice ID trusted application (TA) on Huawei devices running HarmonyOS. This vulnerability ...

Jan 10, 2022
CVE-2021-40021
7.5

CVE-2021-40021 is an out-of-bounds memory write vulnerability in the eID module of HarmonyOS. This vulnerability could allow attackers to write beyond...

Jan 10, 2022
CVE-2021-40028
7.5

CVE-2021-40028 is an out-of-bounds memory write vulnerability in the eID module of HarmonyOS. This vulnerability could allow attackers to corrupt memo...

Jan 10, 2022
CVE-2021-45681
7.5

This vulnerability in the derive-com-impl Rust crate allows memory corruption due to improper reference counting. Attackers could potentially execute ...

Dec 27, 2021
CVE-2021-43399
7.5

This vulnerability in Yubico's YubiHSM2 library allows buffer overflow attacks by not properly validating input lengths for SSH signing and data opera...

Dec 8, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,482 CVEs classified as CWE-787, with 861 rated critical and 2,405 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free