CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,500
Total CVEs
869
Critical
2,415
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 435
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 207
6 Tenda 189
7 Fedoraproject 144
8 Microsoft 106
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,500)

CVE-2019-20840
7.5

CVE-2019-20840 is a memory corruption vulnerability in LibVNCServer's WebSocket decoding functionality that can cause crashes due to unaligned memory ...

Jun 17, 2020
CVE-2020-7502
7.5

This vulnerability allows remote attackers to cause a Denial of Service (DoS) on Schneider Electric Modicon M218 Logic Controllers by sending speciall...

Jun 16, 2020
CVE-2020-4435
7.5

This vulnerability in IBM Aspera applications allows arbitrary memory corruption through the HTTP fallback service when configured in certain ways. An...

Jun 10, 2020
CVE-2020-1260
7.5

This vulnerability allows remote code execution through the VBScript engine when it improperly handles objects in memory. Attackers can exploit this b...

Jun 9, 2020
CVE-2020-1092
7.5

This is a remote code execution vulnerability in Internet Explorer where improper memory access allows attackers to execute arbitrary code. It affects...

May 21, 2020
CVE-2020-1060
7.5

This vulnerability allows remote code execution through malicious VBScript content, enabling attackers to take control of affected systems. It affects...

May 21, 2020
CVE-2020-1062
7.5

This CVE describes a remote code execution vulnerability in Internet Explorer due to improper memory access, allowing attackers to corrupt memory and ...

May 21, 2020
CVE-2020-1035
7.5

This vulnerability allows remote code execution through the VBScript engine when it improperly handles objects in memory. Attackers can exploit this b...

May 21, 2020
CVE-2019-20797
7.5

CVE-2019-20797 is a buffer overflow vulnerability in prboom-plus 2.5.1.5's UDP packet handling code that allows remote attackers to execute arbitrary ...

May 18, 2020
CVE-2019-20799
7.5

CVE-2019-20799 is a memory corruption vulnerability in Cherokee web server that allows remote attackers to cause denial of service or potentially exec...

May 18, 2020
CVE-2020-12672
7.5

CVE-2020-12672 is a heap-based buffer overflow vulnerability in GraphicsMagick's PNG/MNG image processing code. Attackers can exploit this by tricking...

May 6, 2020
CVE-2020-0968
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer's...

Apr 15, 2020
CVE-2020-0970
7.5

This is a remote code execution vulnerability in Microsoft's ChakraCore JavaScript engine that allows attackers to execute arbitrary code by exploitin...

Apr 15, 2020
CVE-2020-10860
7.5

This vulnerability in Avast Antivirus allows attackers to overwrite arbitrary memory addresses in the aswAvLog logging library, causing denial of serv...

Apr 1, 2020
CVE-2019-20601
7.5

This vulnerability allows attackers to write arbitrary data to protected memory regions on Samsung mobile devices with specific Exynos chipsets. It af...

Mar 24, 2020
CVE-2020-7248
7.5

CVE-2020-7248 is a stack-based buffer overflow vulnerability in libubox's JSON serialization in OpenWrt. It allows remote attackers to execute arbitra...

Mar 16, 2020
CVE-2020-0848
7.5

This is a remote code execution vulnerability in ChakraCore, Microsoft's JavaScript engine used in Edge browser. Attackers can exploit memory corrupti...

Mar 12, 2020
CVE-2020-0824
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Internet Explorer. Attacke...

Mar 12, 2020
CVE-2020-0826
7.5

This is a remote code execution vulnerability in Microsoft's ChakraCore JavaScript engine that allows attackers to execute arbitrary code by exploitin...

Mar 12, 2020
CVE-2020-0828
7.5

CVE-2020-0828 is a remote code execution vulnerability in Microsoft's ChakraCore JavaScript engine that allows attackers to execute arbitrary code by ...

Mar 12, 2020
CVE-2020-0830
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft browser s...

Mar 12, 2020
CVE-2020-0832
7.5

This is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code on affected syst...

Mar 12, 2020
CVE-2020-0811
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in the Chakra scriptin...

Mar 12, 2020
CVE-2020-0768
7.5

This is a remote code execution vulnerability in Microsoft browser scripting engines that allows attackers to execute arbitrary code on affected syste...

Mar 12, 2020
CVE-2020-1876
7.5

This vulnerability allows unauthenticated attackers to send specially crafted packets to affected Huawei network security devices, causing an out-of-b...

Feb 28, 2020
CVE-2020-0767
7.5

This is a remote code execution vulnerability in Microsoft's ChakraCore JavaScript engine that allows attackers to execute arbitrary code by exploitin...

Feb 11, 2020
CVE-2020-0711
7.5

This is a remote code execution vulnerability in ChakraCore, Microsoft's JavaScript engine used in Edge browser. Attackers can exploit memory corrupti...

Feb 11, 2020
CVE-2020-0713
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in the ChakraCore scripting e...

Feb 11, 2020
CVE-2020-0673
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer's...

Feb 11, 2020
CVE-2020-6060
7.5

A stack buffer overflow vulnerability in MiniSNMPD version 1.4 allows attackers to cause denial of service by initiating multiple SNMP connections wit...

Feb 4, 2020
CVE-2013-5659
7.5

CVE-2013-5659 is a memory corruption vulnerability in Wiz 5.0.3 that allows user-mode write access violations. This could enable attackers to execute ...

Jan 27, 2020
CVE-2019-20431
7.5

This vulnerability in the Lustre file system allows remote attackers to trigger out-of-bounds memory access and system panic by sending specially craf...

Jan 27, 2020
CVE-2019-20425
7.5

CVE-2019-20425 is an out-of-bounds memory access vulnerability in Lustre file system's ptlrpc module that can cause system panic/crash. It affects Lus...

Jan 27, 2020
CVE-2020-2701
7.5

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to potentially compromise the Virtua...

Jan 15, 2020
CVE-2020-0640
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Internet Explorer. Attacke...

Jan 14, 2020
CVE-2020-6851
7.5

This vulnerability in OpenJPEG allows attackers to execute arbitrary code or cause denial of service via a heap-based buffer overflow when processing ...

Jan 13, 2020
CVE-2019-5275
7.5

This vulnerability affects Huawei USG9500 firewalls with specific firmware versions. A flaw in the X.509 certificate parsing implementation causes a h...

Dec 26, 2019
CVE-2019-5815
7.5

This is a type confusion vulnerability in libxslt's xsltNumberFormatGetMultipleLevel function that could allow heap corruption via specially crafted X...

Dec 11, 2019
CVE-2019-1485
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting how the VBScript engine handles objects in memo...

Dec 10, 2019
CVE-2019-11182
7.5

This vulnerability allows memory corruption in Intel Baseboard Management Controller (BMC) firmware, which could enable an unauthenticated attacker to...

Nov 14, 2019
CVE-2019-8240
7.5

CVE-2019-8240 is a memory corruption vulnerability in Adobe Bridge CC that could allow attackers to read sensitive information from application memory...

Nov 14, 2019
CVE-2019-1426
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Nov 12, 2019
CVE-2019-1428
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Nov 12, 2019
CVE-2019-18840
7.5

This vulnerability in wolfSSL allows attackers to execute arbitrary code or cause denial of service via a specially crafted certificate during TLS han...

Nov 9, 2019
CVE-2019-1371
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Internet Explorer. Attacke...

Oct 10, 2019
CVE-2019-1335
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Oct 10, 2019
CVE-2019-1308
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Oct 10, 2019
CVE-2019-1367
7.5

This is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code on affected syst...

Sep 23, 2019
CVE-2019-1300
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by exploiti...

Sep 11, 2019
CVE-2019-1237
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by exploiti...

Sep 11, 2019

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,500 CVEs classified as CWE-787, with 869 rated critical and 2,415 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free