CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,493
Total CVEs
864
Critical
2,413
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 434
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 206
6 Tenda 189
7 Fedoraproject 144
8 Microsoft 105
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,493)

CVE-2021-40014
7.5

CVE-2021-40014 is a heap overflow vulnerability in the bone voice ID trusted application (TA) on Huawei devices running HarmonyOS. This vulnerability ...

Jan 10, 2022
CVE-2021-40021
7.5

CVE-2021-40021 is an out-of-bounds memory write vulnerability in the eID module of HarmonyOS. This vulnerability could allow attackers to write beyond...

Jan 10, 2022
CVE-2021-40028
7.5

CVE-2021-40028 is an out-of-bounds memory write vulnerability in the eID module of HarmonyOS. This vulnerability could allow attackers to corrupt memo...

Jan 10, 2022
CVE-2021-45681
7.5

This vulnerability in the derive-com-impl Rust crate allows memory corruption due to improper reference counting. Attackers could potentially execute ...

Dec 27, 2021
CVE-2021-43399
7.5

This vulnerability in Yubico's YubiHSM2 library allows buffer overflow attacks by not properly validating input lengths for SSH signing and data opera...

Dec 8, 2021
CVE-2021-42076
7.5

This vulnerability allows an attacker to cause memory exhaustion (denial of service) in Barrier software by sending long TCP messages. It affects both...

Nov 8, 2021
CVE-2021-31374
7.5

This vulnerability allows remote attackers to cause a denial of service on Juniper Networks devices by sending specially crafted BGP UPDATE or KEEPALI...

Oct 19, 2021
CVE-2021-41456
7.5

A stack buffer overflow vulnerability in MP4Box v1.0.1 allows attackers to cause denial of service by exploiting improper bounds checking in the nhmld...

Oct 1, 2021
CVE-2021-41459
7.5

This vulnerability is a stack buffer overflow in MP4Box v1.0.1 that allows attackers to cause denial of service by crashing the application. It affect...

Oct 1, 2021
CVE-2021-32486
7.5

This vulnerability is a heap buffer overflow in the 2G Radio Resource Management (RRM) component of MediaTek modems. It allows remote attackers to cau...

Sep 9, 2021
CVE-2021-32484
7.5

This vulnerability allows remote attackers to cause a denial of service via a heap buffer overflow in the 2G Radio Resource Management (RRM) modem com...

Sep 9, 2021
CVE-2021-3761
7.5

This vulnerability allows any Certificate Authority (CA) issuer in the Resource Public Key Infrastructure (RPKI) to trick OctoRPKI versions prior to 1...

Sep 9, 2021
CVE-2021-1808
7.5

CVE-2021-1808 is a memory corruption vulnerability in Apple operating systems that allows applications to read restricted memory regions. This could l...

Sep 8, 2021
CVE-2020-19131
7.5

This vulnerability is a buffer overflow in LibTiff's tiffcrop utility that allows attackers to cause denial of service through the invertImage() funct...

Sep 7, 2021
CVE-2021-33928
7.5

A buffer overflow vulnerability in libsolv's pool_installable function allows attackers to cause Denial of Service by crashing applications using this...

Sep 2, 2021
CVE-2021-33930
7.5

A buffer overflow vulnerability in libsolv's pool_installable_whatprovides function allows attackers to cause Denial of Service by crashing the applic...

Sep 2, 2021
CVE-2020-20486
7.5

CVE-2020-20486 is a stack buffer overflow vulnerability in IEC104 v1.0's Iec10x_Sta_Addr parameter that allows remote attackers to execute arbitrary c...

Aug 31, 2021
CVE-2020-18735
7.5

CVE-2020-18735 is a heap buffer overflow vulnerability in Eclipse IOT Cyclone DDS Project that allows attackers to crash the DDS subscriber server thr...

Aug 23, 2021
CVE-2020-23332
7.5

A heap-based buffer overflow vulnerability exists in Bento4's AP4_StdcFileByteStream::ReadPartial component, allowing attackers to cause denial of ser...

Aug 17, 2021
CVE-2020-23334
7.5

This vulnerability in Bento4's AP4_NullTerminatedStringAtom component allows attackers to cause a segmentation fault via improper memory write access....

Aug 17, 2021
CVE-2021-35392
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected devices via a heap buffer overflow in Realtek Jungle SDK's WiFi Simpl...

Aug 16, 2021
CVE-2021-38614
7.5

CVE-2021-38614 is a heap-based buffer overflow vulnerability in Polipo caching proxy server versions through 1.1.1 when compiled with NDEBUG flag. Att...

Aug 12, 2021
CVE-2021-38592
7.5

CVE-2021-38592 is a heap-based buffer overflow vulnerability in Wasm3 0.5.0's op_Const64 function that can be triggered during WebAssembly module load...

Aug 12, 2021
CVE-2021-22414
7.5

This is a memory buffer overflow vulnerability (CWE-787) affecting Huawei smartphones. Successful exploitation could allow attackers to cause system r...

Aug 2, 2021
CVE-2021-27628
7.5

CVE-2021-27628 is a denial-of-service vulnerability in SAP NetWeaver ABAP Server and ABAP Platform that allows unauthenticated attackers to crash the ...

Jun 9, 2021
CVE-2021-31684
7.5

A denial-of-service vulnerability exists in JSON Smart's indexOf function that allows attackers to crash applications via specially crafted JSON input...

Jun 1, 2021
CVE-2021-30186
7.5

CVE-2021-30186 is a heap-based buffer overflow vulnerability in CODESYS V2 runtime system SP. This vulnerability allows attackers to execute arbitrary...

May 25, 2021
CVE-2021-26419
7.5

CVE-2021-26419 is a memory corruption vulnerability in Internet Explorer's scripting engine (jscript9.dll) that allows remote code execution. Attacker...

May 11, 2021
CVE-2021-31598
7.5

CVE-2021-31598 is a heap-based buffer overflow vulnerability in ezXML library's ezxml_decode() function that occurs when parsing malicious XML files. ...

Apr 24, 2021
CVE-2021-27799
7.5

CVE-2021-27799 is a stack-based buffer overflow vulnerability in the Zint Barcode Generator library's EAN barcode processing function. Attackers can e...

Feb 26, 2021
CVE-2021-20986
7.5

A Denial of Service vulnerability in Hilscher PROFINET IO Device V3 allows attackers to disrupt industrial communication by causing unexpected loss of...

Feb 16, 2021
CVE-2021-22973
7.5

This vulnerability in F5 BIG-IP's JSON parser allows attackers to perform out-of-bounds memory access or writes, potentially leading to remote code ex...

Feb 12, 2021
CVE-2021-3382
7.5

A stack buffer overflow vulnerability in Gitea versions 1.9.0 through 1.13.1 allows remote attackers to crash the service via specially crafted file p...

Feb 5, 2021
CVE-2020-27541
7.5

CVE-2020-27541 is a denial-of-service vulnerability in Rostelecom CS-C2SHW IP camera firmware. It allows remote attackers to crash the AgentGreen serv...

Jan 26, 2021
CVE-2020-35965
7.5

CVE-2020-35965 is an out-of-bounds write vulnerability in FFmpeg's EXR image decoder that could allow attackers to execute arbitrary code or cause den...

Jan 4, 2021
CVE-2019-25001
7.5

This vulnerability in the serde_cbor Rust crate allows attackers to cause stack exhaustion through specially crafted CBOR data with deeply nested sema...

Dec 31, 2020
CVE-2020-35376
7.5

CVE-2020-35376 is a stack-based buffer overflow vulnerability in Xpdf 4.02's Type 1C font parser. Attackers can craft malicious PDF files to cause den...

Dec 26, 2020
CVE-2020-29363
7.5

This vulnerability is a heap-based buffer overflow in p11-kit's RPC protocol that allows remote attackers to execute arbitrary code or cause denial of...

Dec 16, 2020
CVE-2020-25464
7.5

This heap buffer overflow vulnerability in the Moddable SDK's debug component allows attackers to crash applications or potentially execute arbitrary ...

Dec 4, 2020
CVE-2020-17053
7.5

This is a memory corruption vulnerability in Internet Explorer that could allow an attacker to execute arbitrary code on a victim's system. It affects...

Nov 11, 2020
CVE-2020-24265
7.5

CVE-2020-24265 is a heap buffer overflow vulnerability in tcpreplay's tcpprep utility that allows attackers to cause denial of service through applica...

Oct 19, 2020
CVE-2020-7122
7.5

Two memory corruption vulnerabilities in Aruba CX Switches allow local denial of service attacks against the CDP process. Attackers with local access ...

Sep 23, 2020
CVE-2020-1570
7.5

A memory corruption vulnerability in Internet Explorer's scripting engine allows remote code execution when users visit malicious websites or open spe...

Aug 17, 2020
CVE-2019-20840
7.5

CVE-2019-20840 is a memory corruption vulnerability in LibVNCServer's WebSocket decoding functionality that can cause crashes due to unaligned memory ...

Jun 17, 2020
CVE-2020-7502
7.5

This vulnerability allows remote attackers to cause a Denial of Service (DoS) on Schneider Electric Modicon M218 Logic Controllers by sending speciall...

Jun 16, 2020
CVE-2020-4435
7.5

This vulnerability in IBM Aspera applications allows arbitrary memory corruption through the HTTP fallback service when configured in certain ways. An...

Jun 10, 2020
CVE-2020-1260
7.5

This vulnerability allows remote code execution through the VBScript engine when it improperly handles objects in memory. Attackers can exploit this b...

Jun 9, 2020
CVE-2020-1092
7.5

This is a remote code execution vulnerability in Internet Explorer where improper memory access allows attackers to execute arbitrary code. It affects...

May 21, 2020
CVE-2020-1060
7.5

This vulnerability allows remote code execution through malicious VBScript content, enabling attackers to take control of affected systems. It affects...

May 21, 2020
CVE-2020-1062
7.5

This CVE describes a remote code execution vulnerability in Internet Explorer due to improper memory access, allowing attackers to corrupt memory and ...

May 21, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,493 CVEs classified as CWE-787, with 864 rated critical and 2,413 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free