CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,688
Total CVEs
943
Critical
2,529
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 453
2 Adobe 321
3 Apple 254
4 Linux 235
5 Debian 233
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 152
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,688)

CVE-2023-33627
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers via the UpdateSnat interface at /goform/aspForm. Attackers can exploit thi...

May 31, 2023
CVE-2023-33629
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DeltriggerList interface. A...

May 31, 2023
CVE-2023-33631
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DelSTList interface. Attack...

May 31, 2023
CVE-2023-33633
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the UpdateWanParams interface. ...

May 31, 2023
CVE-2023-33635
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers that allows remote attackers to execute arbitrary code via the UpdateMacCl...

May 31, 2023
CVE-2023-33637
7.2

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R300 routers via a stack overflow in the DelDNSHnList interface. Att...

May 31, 2023
CVE-2023-33639
7.2

This CVE describes a stack overflow vulnerability in H3C Magic R300 routers via the SetMobileAPInfoById interface at /goform/aspForm. Attackers can ex...

May 31, 2023
CVE-2020-20746
7.2

A stack-based buffer overflow vulnerability in the Tenda AC9 router's HTTP server allows remote attackers to execute arbitrary code or cause denial of...

Sep 30, 2021
CVE-2020-19891
7.2

DBHcms v1.2.0 contains an arbitrary file write vulnerability in the editor module that allows authenticated admin users to write arbitrary content to ...

Aug 24, 2020
CVE-2018-21181
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR router, gateway, and extender models. An authenticated attacker can...

Apr 28, 2020
CVE-2018-21175
7.2

This CVE describes a stack-based buffer overflow vulnerability in certain NETGEAR routers and gateways that allows an authenticated attacker to execut...

Apr 27, 2020
CVE-2018-21177
7.2

This vulnerability allows an authenticated attacker to trigger a stack-based buffer overflow on affected NETGEAR routers and gateways. Successful expl...

Apr 27, 2020
CVE-2018-21174
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers and gateways that allows authenticated users to execute arb...

Apr 27, 2020
CVE-2018-21163
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers, gateways, and extenders. An authenticated attacker can exp...

Apr 23, 2020
CVE-2019-20767
7.2

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers and modem-routers that allows authenticated users to execut...

Apr 15, 2020
CVE-2019-15665
7.2

This vulnerability in Rivet Killer Control Center allows local attackers to execute arbitrary code or escalate privileges by exploiting an unvalidated...

Mar 20, 2020
CVE-2019-15661
7.2

This vulnerability in Rivet Killer Control Center allows local attackers to execute arbitrary code or escalate privileges through a stack-based buffer...

Mar 20, 2020
CVE-2019-11542
7.2

This vulnerability allows authenticated attackers with admin web interface access to execute arbitrary code via a stack buffer overflow in Pulse Secur...

Apr 26, 2019
CVE-2025-43520
7.1

This CVE describes a memory corruption vulnerability in Apple operating systems that could allow a malicious application to cause system crashes or wr...

Dec 12, 2025
CVE-2025-43224
7.1

An out-of-bounds memory access vulnerability in Apple's media processing components allows attackers to cause denial of service or potentially execute...

Jul 30, 2025
CVE-2024-0150
7.1

This CVE describes an out-of-bounds write vulnerability in NVIDIA GPU display drivers for Windows and Linux. Attackers could exploit this to cause den...

Jan 28, 2025
CVE-2025-24118
7.1

This is a memory corruption vulnerability in Apple operating systems that allows malicious applications to cause system crashes or write to kernel mem...

Jan 27, 2025
CVE-2024-44245
7.1

This vulnerability allows a malicious app to cause system crashes or corrupt kernel memory on Apple devices. It affects users running vulnerable versi...

Dec 12, 2024
CVE-2024-46774
7.1

This CVE describes a Spectre v1 vulnerability in the Linux kernel's RTAS (Run-Time Abstraction Services) system call implementation on PowerPC archite...

Sep 18, 2024
CVE-2024-45023
7.1

A race condition in Linux kernel's RAID1 implementation can cause data corruption when reading from degraded arrays with slow disks. This vulnerabilit...

Sep 11, 2024
CVE-2024-42094
7.1

This CVE describes a stack overflow vulnerability in the Linux kernel's net/iucv component when CONFIG_CPUMASK_OFFSTACK=y is configured. The vulnerabi...

Jul 29, 2024
CVE-2024-38621
7.1

This CVE describes a buffer overflow vulnerability in the Linux kernel's stk1160 video driver. The flaw allows attackers to write beyond allocated mem...

Jun 21, 2024
CVE-2024-32917
7.1

This vulnerability allows local privilege escalation on affected Android Pixel devices through an out-of-bounds write in the DMA controller driver. At...

Jun 13, 2024
CVE-2024-26763
7.1

A race condition vulnerability in the Linux kernel's dm-crypt subsystem when using authenticated encryption (AEAD) allows data corruption. Attackers w...

Apr 3, 2024
CVE-2024-26674
7.1

A Linux kernel vulnerability in x86 architecture memory access functions causes kernel panic during hardware memory errors when accessing userspace me...

Apr 2, 2024
CVE-2024-26664
7.1

This CVE-2024-26664 is an out-of-bounds memory access vulnerability in the Linux kernel's coretemp hardware monitoring driver. It allows attackers wit...

Apr 2, 2024
CVE-2024-26669
7.1

A memory leak vulnerability in the Linux kernel's net/sched subsystem when using flower classifier chain templates. When a qdisc is deleted, the kerne...

Apr 2, 2024
CVE-2023-52628
7.1

This vulnerability in the Linux kernel's netfilter nftables exthdr component allows a 4-byte out-of-bounds stack write when processing network packets...

Mar 28, 2024
CVE-2024-28318
7.1

This vulnerability in GPAC multimedia framework allows attackers to write data beyond allocated memory boundaries when processing SWF files. It affect...

Mar 15, 2024
CVE-2023-38610
7.1

This CVE describes a memory corruption vulnerability in Apple operating systems that allows malicious applications to cause system crashes or write to...

Jan 10, 2024
CVE-2021-33834
7.1

This vulnerability in Insyde H2OFFT's iscflashx64.sys driver allows attackers to cause memory corruption or system crashes by sending a malformed IOCT...

Sep 8, 2023
CVE-2021-29390
7.1

CVE-2021-29390 is a heap-based buffer over-read vulnerability in libjpeg-turbo's decompress_smooth_data function that allows reading 2 bytes beyond al...

Aug 22, 2023
CVE-2023-21489
7.1

A heap out-of-bounds write vulnerability in Samsung device bootloaders allows physical attackers to execute arbitrary code during the boot process. Th...

May 4, 2023
CVE-2022-29208
7.1

This CVE allows attackers to cause a segmentation fault and denial of service in TensorFlow by passing negative values to the tf.raw_ops.EditDistance ...

May 20, 2022
CVE-2022-23318
7.1

CVE-2022-23318 is a heap buffer overflow vulnerability in pcf2bdf that allows attackers to trigger unsafe memory access via specially crafted PCF font...

Feb 17, 2022
CVE-2020-23060
7.1

Internet Download Manager 6.37.11.1 contains a stack buffer overflow vulnerability in its Export/Import function. Attackers can exploit this by tricki...

Oct 22, 2021
CVE-2020-23267
7.1

This vulnerability in GPAC 0.8.0 allows attackers to cause a heap-based buffer overflow by processing a specially crafted media file. This can lead to...

Sep 22, 2021
CVE-2021-30710
7.1

This memory corruption vulnerability in Apple operating systems allows malicious applications to cause denial of service or potentially leak memory co...

Sep 8, 2021
CVE-2021-1828
7.1

This is a macOS kernel memory corruption vulnerability that allows an application to cause system crashes or write to kernel memory. It affects macOS ...

Sep 8, 2021
CVE-2021-31320
7.1

A heap buffer overflow vulnerability in Telegram's custom rlottie library allows remote attackers to potentially execute arbitrary code or crash the a...

May 18, 2021
CVE-2021-3501
7.1

This vulnerability in the Linux kernel's KVM API allows a user process to trigger an out-of-bounds write by manipulating the internal.ndata value. It ...

May 6, 2021
CVE-2021-25346
7.1

This vulnerability in Samsung's quram library allows attackers to overwrite arbitrary memory locations, potentially leading to arbitrary code executio...

Mar 4, 2021
CVE-2020-11203
7.1

This vulnerability is a stack buffer overflow in Qualcomm Snapdragon chipsets that occurs when processing GSM/WCDMA broadcast configuration data. Atta...

Feb 22, 2021
CVE-2017-18926
7.1

CVE-2017-18926 is a heap-based buffer overflow vulnerability in Raptor RDF Syntax Library's XML writer component. It allows attackers to execute arbit...

Nov 6, 2020
CVE-2020-12654
7.1

This vulnerability allows a remote access point to trigger a heap-based buffer overflow in the Linux kernel's mwifiex wireless driver. Attackers could...

May 5, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,688 CVEs classified as CWE-787, with 943 rated critical and 2,529 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free