CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,511
Total CVEs
870
Critical
2,425
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 435
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 207
6 Tenda 189
7 Fedoraproject 144
8 Microsoft 106
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,511)

CVE-2024-20849
7.3

This CVE describes an out-of-bounds write vulnerability in the chunk parsing implementation of libsdffextractor library on Samsung devices. It allows ...

Apr 2, 2024
CVE-2024-29131
7.3

This CVE describes an out-of-bounds write vulnerability in Apache Commons Configuration that could allow attackers to write data beyond allocated memo...

Mar 21, 2024
CVE-2024-28123
7.3

This vulnerability in the WASMI WebAssembly interpreter allows an out-of-bounds buffer write when the host calls or resumes a Wasm function with more ...

Mar 21, 2024
CVE-2023-42567
7.3

This vulnerability allows attackers to execute arbitrary code or cause denial of service through a stack-based buffer overflow in Samsung's softsimd c...

Dec 5, 2023
CVE-2023-48695
7.3

This vulnerability allows remote code execution through out-of-bounds write flaws in Azure RTOS USBX's USB host and device classes, specifically affec...

Dec 5, 2023
CVE-2023-45676
7.3

CVE-2023-45676 is an integer overflow vulnerability in the stb_vorbis library that can lead to out-of-bounds writes when processing malicious Ogg Vorb...

Oct 21, 2023
CVE-2023-45681
7.3

CVE-2023-45681 is a heap buffer overflow vulnerability in the stb_vorbis library that processes Ogg Vorbis audio files. An attacker can craft a malici...

Oct 21, 2023
CVE-2022-32323
7.3

CVE-2022-32323 is a heap buffer overflow vulnerability in AutoTrace v0.40.0's BMP image processing functionality. Attackers can exploit this by provid...

Jul 14, 2022
CVE-2021-25492
7.3

This vulnerability in Samsung Notes allows attackers to read memory beyond allocated buffer boundaries due to insufficient input validation in the lib...

Oct 6, 2021
CVE-2021-29942
7.3

This vulnerability in the Rust reorder crate allows reading uninitialized memory when swap_index is called with an iterator reporting an incorrect len...

Apr 1, 2021
CVE-2020-7461
7.3

A heap overflow vulnerability in FreeBSD's dhclient allows remote attackers to potentially execute arbitrary code by sending malformed DHCP option 119...

Mar 26, 2021
CVE-2020-4265
7.3

CVE-2020-4265 is a memory corruption vulnerability in IBM i2 Intelligent Analysis Platform 9.2.1 that allows local attackers to execute arbitrary code...

May 14, 2020
CVE-2019-9386
7.3

This vulnerability allows local privilege escalation on Android 10 devices through NFC server. An attacker could gain system-level privileges by explo...

Sep 27, 2019
CVE-2019-9309
7.3

This vulnerability in Android's NFC stack allows local privilege escalation through an out-of-bounds write. Attackers can exploit this by tricking use...

Sep 27, 2019
CVE-2025-37169
7.2

A stack overflow vulnerability in the AOS-10 web management interface of HPE Mobility Gateway allows authenticated attackers to execute arbitrary code...

Jan 13, 2026
CVE-2025-12196
7.2

An authenticated privileged user can exploit an out-of-bounds write vulnerability in WatchGuard Fireware OS's CLI via a specially crafted command to e...

Dec 4, 2025
CVE-2025-12026
7.2

An authenticated privileged user can execute arbitrary code on WatchGuard Fireware OS devices by exploiting an out-of-bounds write vulnerability in th...

Dec 4, 2025
CVE-2025-12195
7.2

An authenticated privileged user can execute arbitrary code on WatchGuard Fireware OS devices by sending specially crafted IPSec configuration command...

Dec 4, 2025
CVE-2024-53697
7.2

This CVE describes an out-of-bounds write vulnerability in QNAP operating systems that could allow remote attackers with administrator access to modif...

Mar 7, 2025
CVE-2024-53699
7.2

An out-of-bounds write vulnerability in QNAP operating systems could allow remote attackers with administrator access to modify or corrupt memory. Thi...

Mar 7, 2025
CVE-2024-38638
7.2

An out-of-bounds write vulnerability in QNAP operating systems allows remote attackers with administrator access to modify or corrupt memory. This aff...

Mar 7, 2025
CVE-2024-35273
7.2

This vulnerability allows attackers to execute arbitrary code with elevated privileges on Fortinet FortiManager and FortiAnalyzer systems through spec...

Jan 14, 2025
CVE-2024-20057
7.2

CVE-2024-20057 is a memory corruption vulnerability in MediaTek's keyInstall component where missing bounds checks allow out-of-bounds writes. This en...

May 6, 2024
CVE-2023-33913
7.2

This CVE describes an out-of-bounds write vulnerability in DRM/oemcrypto due to incorrect buffer size calculation. It could allow remote attackers to ...

Aug 7, 2023
CVE-2023-33641
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the AddMacList interface. Attac...

May 31, 2023
CVE-2023-33643
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers that allows remote attackers to execute arbitrary code via the AddWlanMacL...

May 31, 2023
CVE-2023-33627
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers via the UpdateSnat interface at /goform/aspForm. Attackers can exploit thi...

May 31, 2023
CVE-2023-33629
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DeltriggerList interface. A...

May 31, 2023
CVE-2023-33631
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DelSTList interface. Attack...

May 31, 2023
CVE-2023-33633
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the UpdateWanParams interface. ...

May 31, 2023
CVE-2023-33635
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers that allows remote attackers to execute arbitrary code via the UpdateMacCl...

May 31, 2023
CVE-2023-33637
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DelDNSHnList interface. Att...

May 31, 2023
CVE-2023-33639
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers via the SetMobileAPInfoById interface at /goform/aspForm. Attackers can ex...

May 31, 2023
CVE-2020-20746
7.2

A stack-based buffer overflow vulnerability in the Tenda AC9 router's HTTP server allows remote attackers to execute arbitrary code or cause denial of...

Sep 30, 2021
CVE-2020-19891
7.2

DBHcms v1.2.0 contains an arbitrary file write vulnerability in the editor module that allows authenticated admin users to write arbitrary content to ...

Aug 24, 2020
CVE-2018-21181
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR router, gateway, and extender models. An authenticated attacker can...

Apr 28, 2020
CVE-2018-21175
7.2

This CVE describes a stack-based buffer overflow vulnerability in certain NETGEAR routers and gateways that allows an authenticated attacker to execut...

Apr 27, 2020
CVE-2018-21177
7.2

This vulnerability allows an authenticated attacker to trigger a stack-based buffer overflow on affected NETGEAR routers and gateways. Successful expl...

Apr 27, 2020
CVE-2018-21174
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers and gateways that allows authenticated users to execute arb...

Apr 27, 2020
CVE-2018-21163
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers, gateways, and extenders. An authenticated attacker can exp...

Apr 23, 2020
CVE-2019-20767
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers and modem-routers that allows authenticated users to execut...

Apr 15, 2020
CVE-2019-15665
7.2

This vulnerability in Rivet Killer Control Center allows local attackers to execute arbitrary code or escalate privileges by exploiting an unvalidated...

Mar 20, 2020
CVE-2019-15661
7.2

This vulnerability in Rivet Killer Control Center allows local attackers to execute arbitrary code or escalate privileges through a stack-based buffer...

Mar 20, 2020
CVE-2025-43520
7.1

This CVE describes a memory corruption vulnerability in Apple operating systems that could allow a malicious application to cause system crashes or wr...

Dec 12, 2025
CVE-2025-43224
7.1

An out-of-bounds memory access vulnerability in Apple's media processing components allows attackers to cause denial of service or potentially execute...

Jul 30, 2025
CVE-2024-0150
7.1

This CVE describes an out-of-bounds write vulnerability in NVIDIA GPU display drivers for Windows and Linux. Attackers could exploit this to cause den...

Jan 28, 2025
CVE-2025-24118
7.1

This is a memory corruption vulnerability in Apple operating systems that allows malicious applications to cause system crashes or write to kernel mem...

Jan 27, 2025
CVE-2024-44245
7.1

This vulnerability allows a malicious app to cause system crashes or corrupt kernel memory on Apple devices. It affects users running vulnerable versi...

Dec 12, 2024
CVE-2024-46774
7.1

This CVE describes a Spectre v1 vulnerability in the Linux kernel's RTAS (Run-Time Abstraction Services) system call implementation on PowerPC archite...

Sep 18, 2024
CVE-2024-45023
7.1

A race condition in Linux kernel's RAID1 implementation can cause data corruption when reading from degraded arrays with slow disks. This vulnerabilit...

Sep 11, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,511 CVEs classified as CWE-787, with 870 rated critical and 2,425 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free