CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,511
Total CVEs
870
Critical
2,425
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
104
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 435
2 Adobe 300
3 Apple 247
4 Linux 234
5 Debian 207
6 Tenda 189
7 Fedoraproject 144
8 Microsoft 106
9 Mozilla 82
10 Samsung 78

All Out-of-bounds Write CVEs (3,511)

CVE-2024-42094
7.1

This CVE describes a stack overflow vulnerability in the Linux kernel's net/iucv component when CONFIG_CPUMASK_OFFSTACK=y is configured. The vulnerabi...

Jul 29, 2024
CVE-2024-38621
7.1

This CVE describes a buffer overflow vulnerability in the Linux kernel's stk1160 video driver. The flaw allows attackers to write beyond allocated mem...

Jun 21, 2024
CVE-2024-32917
7.1

This vulnerability allows local privilege escalation on affected Android Pixel devices through an out-of-bounds write in the DMA controller driver. At...

Jun 13, 2024
CVE-2024-26763
7.1

A race condition vulnerability in the Linux kernel's dm-crypt subsystem when using authenticated encryption (AEAD) allows data corruption. Attackers w...

Apr 3, 2024
CVE-2024-26674
7.1

A Linux kernel vulnerability in x86 architecture memory access functions causes kernel panic during hardware memory errors when accessing userspace me...

Apr 2, 2024
CVE-2024-26664
7.1

This CVE-2024-26664 is an out-of-bounds memory access vulnerability in the Linux kernel's coretemp hardware monitoring driver. It allows attackers wit...

Apr 2, 2024
CVE-2024-26669
7.1

A memory leak vulnerability in the Linux kernel's net/sched subsystem when using flower classifier chain templates. When a qdisc is deleted, the kerne...

Apr 2, 2024
CVE-2023-52628
7.1

This vulnerability in the Linux kernel's netfilter nftables exthdr component allows a 4-byte out-of-bounds stack write when processing network packets...

Mar 28, 2024
CVE-2024-28318
7.1

This vulnerability in GPAC multimedia framework allows attackers to write data beyond allocated memory boundaries when processing SWF files. It affect...

Mar 15, 2024
CVE-2023-38610
7.1

This CVE describes a memory corruption vulnerability in Apple operating systems that allows malicious applications to cause system crashes or write to...

Jan 10, 2024
CVE-2021-33834
7.1

This vulnerability in Insyde H2OFFT's iscflashx64.sys driver allows attackers to cause memory corruption or system crashes by sending a malformed IOCT...

Sep 8, 2023
CVE-2021-29390
7.1

CVE-2021-29390 is a heap-based buffer over-read vulnerability in libjpeg-turbo's decompress_smooth_data function that allows reading 2 bytes beyond al...

Aug 22, 2023
CVE-2023-21489
7.1

A heap out-of-bounds write vulnerability in Samsung device bootloaders allows physical attackers to execute arbitrary code during the boot process. Th...

May 4, 2023
CVE-2022-29208
7.1

This CVE allows attackers to cause a segmentation fault and denial of service in TensorFlow by passing negative values to the tf.raw_ops.EditDistance ...

May 20, 2022
CVE-2022-23318
7.1

CVE-2022-23318 is a heap buffer overflow vulnerability in pcf2bdf that allows attackers to trigger unsafe memory access via specially crafted PCF font...

Feb 17, 2022
CVE-2020-23060
7.1

Internet Download Manager 6.37.11.1 contains a stack buffer overflow vulnerability in its Export/Import function. Attackers can exploit this by tricki...

Oct 22, 2021
CVE-2020-23267
7.1

This vulnerability in GPAC 0.8.0 allows attackers to cause a heap-based buffer overflow by processing a specially crafted media file. This can lead to...

Sep 22, 2021
CVE-2021-30710
7.1

This memory corruption vulnerability in Apple operating systems allows malicious applications to cause denial of service or potentially leak memory co...

Sep 8, 2021
CVE-2021-1828
7.1

This is a macOS kernel memory corruption vulnerability that allows an application to cause system crashes or write to kernel memory. It affects macOS ...

Sep 8, 2021
CVE-2021-31320
7.1

A heap buffer overflow vulnerability in Telegram's custom rlottie library allows remote attackers to potentially execute arbitrary code or crash the a...

May 18, 2021
CVE-2021-3501
7.1

This vulnerability in the Linux kernel's KVM API allows a user process to trigger an out-of-bounds write by manipulating the internal.ndata value. It ...

May 6, 2021
CVE-2021-25346
7.1

This vulnerability in Samsung's quram library allows attackers to overwrite arbitrary memory locations, potentially leading to arbitrary code executio...

Mar 4, 2021
CVE-2020-11203
7.1

This vulnerability is a stack buffer overflow in Qualcomm Snapdragon chipsets that occurs when processing GSM/WCDMA broadcast configuration data. Atta...

Feb 22, 2021
CVE-2017-18926
7.1

CVE-2017-18926 is a heap-based buffer overflow vulnerability in Raptor RDF Syntax Library's XML writer component. It allows attackers to execute arbit...

Nov 6, 2020
CVE-2020-12654
7.1

This vulnerability allows a remote access point to trigger a heap-based buffer overflow in the Linux kernel's mwifiex wireless driver. Attackers could...

May 5, 2020
CVE-2019-8545
7.1

CVE-2019-8545 is a memory corruption vulnerability in Apple operating systems that allows local users to cause system crashes or read kernel memory. T...

Dec 18, 2019
CVE-2025-68119
7.0

This vulnerability allows attackers to execute arbitrary code or write arbitrary files when downloading and building Go modules with malicious version...

Jan 28, 2026
CVE-2025-21006
7.0

This vulnerability allows local attackers to write out-of-bounds memory in the MPEG4 codec handling within libsavsvc.so on Android devices. It affects...

Jul 8, 2025
CVE-2025-20671
7.0

This CVE describes a local privilege escalation vulnerability in MediaTek thermal management components. An attacker with System privilege can exploit...

May 5, 2025
CVE-2025-20890
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on Samsung devices by exploiting an out-of-bounds write i...

Feb 4, 2025
CVE-2025-20882
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...

Feb 4, 2025
CVE-2025-20888
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...

Feb 4, 2025
CVE-2025-20881
7.0

This vulnerability is an out-of-bounds write in libsthmbc.so video decoding library that allows local attackers to execute arbitrary code with elevate...

Feb 4, 2025
CVE-2023-34305
7.0

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...

May 3, 2024
CVE-2024-26730
7.0

This CVE describes a memory access vulnerability in the Linux kernel's nct6775 hardware monitoring driver. It allows out-of-bounds read/write operatio...

Apr 3, 2024
CVE-2023-48229
7.0

An out-of-bounds write vulnerability in Contiki-NG's IEEE 802.15.4 radio driver allows attackers to write beyond allocated buffer boundaries when pars...

Feb 14, 2024
CVE-2024-0646
7.0

This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's TLS implementation when using splice() with ktls sockets. A local...

Jan 17, 2024
CVE-2023-32832
7.0

This CVE describes a race condition vulnerability in the MediaTek JPEG driver for Android devices that allows local privilege escalation without user ...

Nov 6, 2023
CVE-2023-42753
7.0

This CVE-2023-42753 is an array indexing vulnerability in the Linux kernel's netfilter subsystem that allows local attackers to perform out-of-bounds ...

Sep 25, 2023
CVE-2023-26923
7.0

MuseScore 3.0 through 4.0.1 contains a stack buffer overflow vulnerability when processing malformed MIDI files. This allows attackers to potentially ...

Mar 28, 2023
CVE-2021-3697
7.0

CVE-2021-3697 is a heap buffer underflow vulnerability in GRUB2's JPEG parser that allows a crafted JPEG image to corrupt heap memory. Successful expl...

Jul 6, 2022
CVE-2022-26743
7.0

CVE-2022-26743 is an out-of-bounds write vulnerability in macOS that allows attackers who have already achieved code execution in macOS Recovery to es...

May 26, 2022
CVE-2022-21882
7.0

CVE-2022-21882 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affects...

Jan 11, 2022
CVE-2020-28198
7.0

CVE-2020-28198 is a stack buffer overflow vulnerability in IBM Tivoli Storage Manager's administrative client (dsmadmc.exe) that allows attackers to e...

May 6, 2021
CVE-2020-1477
7.0

CVE-2020-1477 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with user privileges. I...

Aug 17, 2020
CVE-2025-20696
6.8

This CVE describes an out-of-bounds write vulnerability in DA (likely a MediaTek component) that could allow local privilege escalation. Attackers wit...

Aug 4, 2025
CVE-2025-20656
6.8

This vulnerability in MediaTek DA software allows local attackers with physical access to escalate privileges through an out-of-bounds write. No user ...

Apr 7, 2025
CVE-2025-20650
6.8

This CVE describes an out-of-bounds write vulnerability in MediaTek's da component that could allow local privilege escalation. Attackers with physica...

Mar 3, 2025
CVE-2024-0143
6.8

This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by providing a specially crafted JPEG...

Feb 12, 2025
CVE-2024-0142
6.8

This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by exploiting an out-of-bounds write ...

Feb 12, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,511 CVEs classified as CWE-787, with 870 rated critical and 2,425 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free