CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,510
Total CVEs
869
Critical
2,425
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 435
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 207
6 Tenda 189
7 Fedoraproject 144
8 Microsoft 106
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,510)

CVE-2019-8240
7.5

CVE-2019-8240 is a memory corruption vulnerability in Adobe Bridge CC that could allow attackers to read sensitive information from application memory...

Nov 14, 2019
CVE-2019-1426
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Nov 12, 2019
CVE-2019-1428
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Nov 12, 2019
CVE-2019-18840
7.5

This vulnerability in wolfSSL allows attackers to execute arbitrary code or cause denial of service via a specially crafted certificate during TLS han...

Nov 9, 2019
CVE-2019-1371
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Internet Explorer. Attacke...

Oct 10, 2019
CVE-2019-1335
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Oct 10, 2019
CVE-2019-1308
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Oct 10, 2019
CVE-2019-1367
7.5

This is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code on affected syst...

Sep 23, 2019
CVE-2019-1300
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by exploiti...

Sep 11, 2019
CVE-2019-1237
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by exploiti...

Sep 11, 2019
CVE-2019-1217
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in the Chakra scriptin...

Sep 11, 2019
CVE-2019-1221
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems through Internet Explorer's scripting engine memory corruptio...

Sep 11, 2019
CVE-2019-16226
7.5

CVE-2019-16226 is a memory corruption vulnerability in py-lmdb 0.97 where mdb_node_del fails to validate a memmove operation when processing a malicio...

Sep 11, 2019
CVE-2019-10056
7.5

This vulnerability in Suricata allows remote attackers to cause a denial of service (crash) by sending specially crafted network packets. It affects S...

Aug 28, 2019
CVE-2019-1194
7.5

This is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code by corrupting me...

Aug 14, 2019
CVE-2019-1133
7.5

A remote code execution vulnerability in Internet Explorer's scripting engine allows attackers to execute arbitrary code by corrupting memory when use...

Aug 14, 2019
CVE-2019-1104
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Microsoft browsers. Attack...

Jul 15, 2019
CVE-2019-1107
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in the Chakra scriptin...

Jul 15, 2019
CVE-2019-1092
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Jul 15, 2019
CVE-2019-1004
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems through memory corruption in Internet Explorer's scripting en...

Jul 15, 2019
CVE-2019-1059
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer's...

Jul 15, 2019
CVE-2019-1063
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer. ...

Jul 15, 2019
CVE-2018-11424
7.5

This vulnerability allows memory corruption in the web interface of Moxa OnCell G3470A-LTE Series devices. Attackers could potentially execute arbitra...

Jul 3, 2019
CVE-2026-25569
7.4

An out-of-bounds write vulnerability in SICAM SIAPP SDK allows attackers to write data beyond allocated buffers. This could lead to denial of service ...

Mar 10, 2026
CVE-2025-69419
7.4

This OpenSSL vulnerability allows memory corruption via a malicious PKCS#12 file containing non-ASCII BMP characters in the friendly name field. When ...

Jan 27, 2026
CVE-2025-33029
7.4

An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi software for Windows allows unprivileged attackers on the same network to cause den...

Nov 11, 2025
CVE-2025-49492
7.4

This CVE describes an out-of-bounds write vulnerability in the ASR180x LTE telephony component's dev_api.C file, which could allow attackers to execut...

Jul 1, 2025
CVE-2024-32921
7.4

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the lwis_fence.c component. Attacke...

Jun 13, 2024
CVE-2024-29740
7.4

CVE-2024-29740 is an out-of-bounds write vulnerability in the tmu_set_table function of tmu.c in Android's kernel. This allows local attackers to esca...

Apr 5, 2024
CVE-2024-26001
7.4

This vulnerability allows unauthenticated remote attackers to write memory out of bounds via improper input validation in the MQTT stack. It affects s...

Mar 12, 2024
CVE-2023-42560
7.4

This vulnerability allows attackers to write data beyond the allocated heap buffer in Samsung's libsavsac.so library, potentially leading to arbitrary...

Dec 5, 2023
CVE-2021-36134
7.4

An out-of-bounds write vulnerability in the JPEG parsing code of Netop Vision Pro allows an adjacent unauthenticated attacker to write to arbitrary me...

Sep 27, 2021
CVE-2021-3713
7.4

This vulnerability allows a malicious guest user in QEMU virtual machines to perform out-of-bounds writes in the UAS device emulation, potentially lea...

Aug 25, 2021
CVE-2025-27821
7.3

This CVE describes an out-of-bounds write vulnerability in Apache Hadoop HDFS native client that could allow attackers to execute arbitrary code or ca...

Jan 26, 2026
CVE-2025-14332
7.3

Memory safety bugs in Firefox and Thunderbird could allow attackers to corrupt memory and potentially execute arbitrary code. This affects all users r...

Dec 9, 2025
CVE-2025-22833
7.3

This CVE describes a buffer overflow vulnerability in AMI APTIOV BIOS firmware where an attacker with local access can execute arbitrary code by explo...

Oct 14, 2025
CVE-2025-47726
7.3

Delta Electronics CNCSoft has an out-of-bounds write vulnerability (CWE-787) due to improper file validation. When users open malicious files, attacke...

Jun 4, 2025
CVE-2025-47728
7.3

Delta Electronics CNCSoft-G2 has a memory corruption vulnerability due to improper file validation. Attackers can execute arbitrary code by tricking u...

Jun 4, 2025
CVE-2025-47724
7.3

Delta Electronics CNCSoft has an out-of-bounds write vulnerability (CWE-787) due to improper validation of user-supplied files. When a user opens a ma...

Jun 4, 2025
CVE-2025-5272
7.3

Memory safety vulnerabilities in Firefox and Thunderbird could allow attackers to corrupt memory and potentially execute arbitrary code. This affects ...

May 27, 2025
CVE-2025-20931
7.3

This vulnerability allows local attackers to execute arbitrary code by exploiting an out-of-bounds write when parsing BMP images in Samsung Notes. Att...

Mar 6, 2025
CVE-2025-20929
7.3

This vulnerability allows local attackers to execute arbitrary code by exploiting an out-of-bounds write when parsing JPEG images in Samsung Notes. At...

Mar 6, 2025
CVE-2024-11345
7.3

A heap-based memory vulnerability in the Postscript interpreter of Lexmark devices allows attackers to execute arbitrary code by sending specially cra...

Feb 13, 2025
CVE-2024-11157
7.3

A memory corruption vulnerability in Rockwell Automation Arena allows attackers to write beyond allocated memory boundaries in DOE files. This could l...

Dec 19, 2024
CVE-2024-43688
7.3

CVE-2024-43688 is a heap-based buffer underflow vulnerability in vixie cron that allows memory corruption. This could potentially lead to arbitrary co...

Aug 20, 2024
CVE-2024-34612
7.3

This vulnerability is an out-of-bounds write in Samsung's libcodec2secmp4vdec.so library that allows local attackers to execute arbitrary code with el...

Aug 7, 2024
CVE-2024-34614
7.3

This vulnerability is an out-of-bounds write in libsmat.so that allows local attackers to execute arbitrary code with elevated privileges. It affects ...

Aug 7, 2024
CVE-2024-20877
7.3

This vulnerability allows local attackers to execute arbitrary code on affected Samsung devices by exploiting a heap out-of-bounds write in the libsav...

Jun 4, 2024
CVE-2021-47441
7.3

A vulnerability in the Linux kernel's mlxsw thermal driver allows setting cooling states above the maximum supported level, leading to out-of-bounds m...

May 22, 2024
CVE-2024-20849
7.3

This CVE describes an out-of-bounds write vulnerability in the chunk parsing implementation of libsdffextractor library on Samsung devices. It allows ...

Apr 2, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,510 CVEs classified as CWE-787, with 869 rated critical and 2,425 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free