CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,674
Total CVEs
940
Critical
2,518
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 450
2 Adobe 321
3 Apple 254
4 Linux 235
5 Debian 228
6 Tenda 189
7 Fedoraproject 152
8 Microsoft 152
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,674)

CVE-2019-0937
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by exploiti...

May 16, 2019
CVE-2019-0912
7.5

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code on affected...

May 16, 2019
CVE-2019-0914
7.5

A memory corruption vulnerability in Microsoft Edge's Chakra JavaScript engine allows remote attackers to execute arbitrary code on affected systems. ...

May 16, 2019
CVE-2019-0916
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in the Chakra scriptin...

May 16, 2019
CVE-2019-0918
7.5

This is a remote code execution vulnerability in Microsoft's scripting engine that allows attackers to execute arbitrary code on affected systems. It ...

May 16, 2019
CVE-2019-0922
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

May 16, 2019
CVE-2019-0884
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft's scripti...

May 16, 2019
CVE-2019-9017
7.5

This vulnerability in SolarWinds DameWare Mini Remote Control allows attackers to cause a buffer overflow by manipulating the machine name size field....

May 2, 2019
CVE-2019-0861
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's Ch...

Apr 9, 2019
CVE-2019-0806
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Microsoft Edge's Chakra Ja...

Apr 9, 2019
CVE-2019-0812
7.5

A memory corruption vulnerability in Microsoft Edge's Chakra JavaScript engine allows remote attackers to execute arbitrary code on affected systems. ...

Apr 9, 2019
CVE-2019-0739
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Apr 9, 2019
CVE-2019-0753
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer's...

Apr 9, 2019
CVE-2019-10896
7.5

CVE-2019-10896 is a denial-of-service vulnerability in Wireshark's DOF dissector that could cause the application to crash when processing specially c...

Apr 9, 2019
CVE-2019-0770
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Apr 9, 2019
CVE-2019-0779
7.5

This is a remote code execution vulnerability in Microsoft Edge's JavaScript engine that allows attackers to execute arbitrary code on affected system...

Apr 9, 2019
CVE-2019-0783
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer's...

Apr 9, 2019
CVE-2019-0763
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Internet Explorer. Attacke...

Apr 9, 2019
CVE-2019-0769
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Apr 9, 2019
CVE-2019-0680
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems through memory corruption in Internet Explorer's scripting en...

Apr 9, 2019
CVE-2019-0592
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in the Chakra scriptin...

Apr 8, 2019
CVE-2019-0609
7.5

This is a remote code execution vulnerability in Microsoft's scripting engine that allows attackers to execute arbitrary code on affected systems. It ...

Apr 8, 2019
CVE-2019-0665
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by exploiting a memory handling flaw in the VBScript ...

Apr 8, 2019
CVE-2019-0667
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by exploiting a memory handling flaw in the VBScript ...

Apr 8, 2019
CVE-2019-9770
7.5

A heap-based buffer overflow vulnerability exists in GNU LibreDWG's dwg_decode_eed_data function when processing the y dimension. This allows attacker...

Mar 14, 2019
CVE-2019-0634
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting memory corruption in Microsoft Edge. Attackers ...

Mar 5, 2019
CVE-2019-0642
7.5

This is a remote code execution vulnerability in Microsoft Edge's scripting engine that allows attackers to execute arbitrary code by exploiting memor...

Mar 5, 2019
CVE-2019-0644
7.5

This is a remote code execution vulnerability in Microsoft Edge's scripting engine that allows attackers to execute arbitrary code by exploiting memor...

Mar 5, 2019
CVE-2019-0651
7.5

This is a remote code execution vulnerability in Microsoft Edge's scripting engine that allows attackers to execute arbitrary code on affected systems...

Mar 5, 2019
CVE-2019-0655
7.5

This is a remote code execution vulnerability in Microsoft Edge's scripting engine that allows attackers to execute arbitrary code on affected systems...

Mar 5, 2019
CVE-2019-0590
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems through memory corruption in Microsoft Edge's scripting engin...

Mar 5, 2019
CVE-2019-0593
7.5

This is a remote code execution vulnerability in Microsoft Edge's scripting engine that allows attackers to execute arbitrary code by exploiting memor...

Mar 5, 2019
CVE-2019-0606
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Internet Explorer. ...

Mar 5, 2019
CVE-2019-0610
7.5

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a memory corruption flaw in Microsoft Edge's sc...

Mar 5, 2019
CVE-2026-25569
7.4

An out-of-bounds write vulnerability in SICAM SIAPP SDK allows attackers to write data beyond allocated buffers. This could lead to denial of service ...

Mar 10, 2026
CVE-2025-69419
7.4

This OpenSSL vulnerability allows memory corruption via a malicious PKCS#12 file containing non-ASCII BMP characters in the friendly name field. When ...

Jan 27, 2026
CVE-2025-33029
7.4

An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi software for Windows allows unprivileged attackers on the same network to cause den...

Nov 11, 2025
CVE-2025-49492
7.4

This CVE describes an out-of-bounds write vulnerability in the ASR180x LTE telephony component's dev_api.C file, which could allow attackers to execut...

Jul 1, 2025
CVE-2024-32921
7.4

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the lwis_fence.c component. Attacke...

Jun 13, 2024
CVE-2024-29740
7.4

CVE-2024-29740 is an out-of-bounds write vulnerability in the tmu_set_table function of tmu.c in Android's kernel. This allows local attackers to esca...

Apr 5, 2024
CVE-2024-26001
7.4

This vulnerability allows unauthenticated remote attackers to write memory out of bounds via improper input validation in the MQTT stack. It affects s...

Mar 12, 2024
CVE-2023-42560
7.4

This vulnerability allows attackers to write data beyond the allocated heap buffer in Samsung's libsavsac.so library, potentially leading to arbitrary...

Dec 5, 2023
CVE-2021-36134
7.4

An out-of-bounds write vulnerability in the JPEG parsing code of Netop Vision Pro allows an adjacent unauthenticated attacker to write to arbitrary me...

Sep 27, 2021
CVE-2021-3713
7.4

This vulnerability allows a malicious guest user in QEMU virtual machines to perform out-of-bounds writes in the UAS device emulation, potentially lea...

Aug 25, 2021
CVE-2025-27821
7.3

This CVE describes an out-of-bounds write vulnerability in Apache Hadoop HDFS native client that could allow attackers to execute arbitrary code or ca...

Jan 26, 2026
CVE-2025-14332
7.3

Memory safety bugs in Firefox and Thunderbird could allow attackers to corrupt memory and potentially execute arbitrary code. This affects all users r...

Dec 9, 2025
CVE-2025-22833
7.3

This CVE describes a buffer overflow vulnerability in AMI APTIOV BIOS firmware where an attacker with local access can execute arbitrary code by explo...

Oct 14, 2025
CVE-2025-47726
7.3

Delta Electronics CNCSoft has an out-of-bounds write vulnerability (CWE-787) due to improper file validation. When users open malicious files, attacke...

Jun 4, 2025
CVE-2025-47728
7.3

Delta Electronics CNCSoft-G2 has a memory corruption vulnerability due to improper file validation. Attackers can execute arbitrary code by tricking u...

Jun 4, 2025
CVE-2025-47724
7.3

Delta Electronics CNCSoft has an out-of-bounds write vulnerability (CWE-787) due to improper validation of user-supplied files. When a user opens a ma...

Jun 4, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,674 CVEs classified as CWE-787, with 940 rated critical and 2,518 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free