CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,704
Total CVEs
612
Critical
1,879
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,704)

CVE-2023-29693
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C GR-1200W MiniGRW1A0V100R006 routers via a stack overflow in the set_tftp_u...

May 8, 2023
CVE-2023-31470
9.8

CVE-2023-31470 is a critical stack-based buffer overflow vulnerability in SmartDNS that allows remote code execution via crafted DNS requests. Attacke...

Apr 28, 2023
CVE-2023-27973
9.8

This critical vulnerability in certain HP LaserJet Pro printers allows attackers to execute arbitrary code remotely via heap overflow. Affected organi...

Apr 28, 2023
CVE-2023-24823
9.8

CVE-2023-24823 is a critical memory corruption vulnerability in RIOT-OS's 6LoWPAN network stack that allows type confusion between IPv6 extension head...

Apr 24, 2023
CVE-2023-30372
9.8

This CVE describes a stack-based buffer overflow vulnerability in the 'xkjs_ver32' function of Tenda AC15 routers. Attackers can exploit this to execu...

Apr 24, 2023
CVE-2023-30375
9.8

This CVE describes a stack-based buffer overflow vulnerability in the 'getIfIp' function of Tenda AC15 routers running firmware version V15.03.05.19. ...

Apr 24, 2023
CVE-2023-30378
9.8

A stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted reque...

Apr 24, 2023
CVE-2023-30370
9.8

CVE-2023-30370 is a critical stack-based buffer overflow vulnerability in Tenda AC15 routers' GetValue function. Attackers can exploit this to execute...

Apr 24, 2023
CVE-2023-30368
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC5 routers via a buffer overflow in the initWebs function. Attackers ca...

Apr 24, 2023
CVE-2023-29665
9.8

CVE-2023-29665 is a critical stack overflow vulnerability in D-Link DIR823G routers that allows remote attackers to execute arbitrary code by sending ...

Apr 17, 2023
CVE-2022-46709
9.8

This is a critical memory corruption vulnerability in Apple's macOS and iOS kernels that allows malicious applications to execute arbitrary code with ...

Apr 10, 2023
CVE-2023-27718
9.8

This vulnerability in D-Link DIR878 routers allows attackers to cause denial of service or execute arbitrary code by sending a specially crafted paylo...

Apr 9, 2023
CVE-2023-27720
9.8

CVE-2023-27720 is a critical stack overflow vulnerability in D-Link DIR878 routers that allows attackers to cause denial of service or execute arbitra...

Apr 9, 2023
CVE-2023-25216
9.8

CVE-2023-25216 is a critical stack overflow vulnerability in Tenda AC5 routers that allows attackers to cause denial of service or execute arbitrary c...

Apr 7, 2023
CVE-2023-25218
9.8

CVE-2023-25218 is a critical stack overflow vulnerability in Tenda AC5 routers that allows attackers to cause denial of service or execute arbitrary c...

Apr 7, 2023
CVE-2023-25220
9.8

This CVE describes a critical stack overflow vulnerability in Tenda AC5 routers via the add_white_node function. Attackers can exploit this to cause d...

Apr 7, 2023
CVE-2023-27013
9.8

This vulnerability in Tenda AC10 routers allows attackers to trigger a stack overflow via the get_parentControl_list_Info function. Attackers can caus...

Apr 7, 2023
CVE-2023-27015
9.8

This vulnerability in Tenda AC10 routers allows attackers to cause denial of service or execute arbitrary code by exploiting a stack overflow in the s...

Apr 7, 2023
CVE-2023-27017
9.8

CVE-2023-27017 is a critical stack overflow vulnerability in Tenda AC10 routers that allows attackers to cause denial of service or execute arbitrary ...

Apr 7, 2023
CVE-2023-27019
9.8

This CVE describes a critical stack overflow vulnerability in Tenda AC10 routers that allows attackers to execute arbitrary code or cause denial of se...

Apr 7, 2023
CVE-2023-27021
9.8

This vulnerability in Tenda AC10 routers allows attackers to cause denial of service or execute arbitrary code by exploiting a stack overflow in the f...

Apr 7, 2023
CVE-2023-24797
9.8

This vulnerability is a stack overflow in D-Link DIR882 routers that allows attackers to cause denial of service or execute arbitrary code via crafted...

Apr 7, 2023
CVE-2023-24799
9.8

CVE-2023-24799 is a critical stack overflow vulnerability in D-Link DIR878 routers that allows attackers to cause denial of service or execute arbitra...

Apr 7, 2023
CVE-2023-25210
9.8

CVE-2023-25210 is a critical stack overflow vulnerability in Tenda AC5 routers that allows attackers to cause denial of service or execute arbitrary c...

Apr 7, 2023
CVE-2023-25212
9.8

CVE-2023-25212 is a critical stack overflow vulnerability in Tenda AC5 routers that allows attackers to cause denial of service or execute arbitrary c...

Apr 7, 2023
CVE-2023-25214
9.8

CVE-2023-25214 is a critical stack overflow vulnerability in Tenda AC5 routers that allows attackers to cause denial of service or execute arbitrary c...

Apr 7, 2023
CVE-2020-19693
9.8

This vulnerability in Espruino allows attackers to execute arbitrary code by exploiting the oldFunc parameter in the jswrap_object.c:jswrap_function_r...

Apr 4, 2023
CVE-2023-28879
9.8

This CVE describes a buffer overflow vulnerability in Artifex Ghostscript's PostScript interpreter that could allow attackers to corrupt internal data...

Mar 31, 2023
CVE-2022-45460
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected Xiongmai NVR devices by sending a specially ...

Mar 28, 2023
CVE-2023-21057
9.8

This critical vulnerability in the Android kernel allows remote attackers to execute arbitrary code without user interaction. It affects Android devic...

Mar 24, 2023
CVE-2023-20951
9.8

This critical vulnerability in Android's Bluetooth GATT implementation allows remote attackers to execute arbitrary code without user interaction. It ...

Mar 24, 2023
CVE-2023-20954
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. It affects Android versions...

Mar 24, 2023
CVE-2023-1529
9.8

This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds memory access in Chrome's WebHID implementation. Attackers...

Mar 21, 2023
CVE-2023-26805
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda W20E routers via a buffer overflow in the formIPMacBindModify function. ...

Mar 19, 2023
CVE-2023-27239
9.8

CVE-2023-27239 is a critical stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code by sending speci...

Mar 15, 2023
CVE-2023-22751
9.8

CVE-2023-22751 is a critical stack-based buffer overflow vulnerability in Aruba Networks' PAPI protocol that allows unauthenticated attackers to execu...

Mar 1, 2023
CVE-2022-26760
9.8

CVE-2022-26760 is a critical memory corruption vulnerability in Apple iOS/iPadOS that allows malicious applications to gain elevated system privileges...

Feb 27, 2023
CVE-2023-25231
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda W30E routers via a buffer overflow in the fromRouteStatic function. Atta...

Feb 27, 2023
CVE-2023-25234
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC500 routers via a buffer overflow in the fromAddressNat function. Atta...

Feb 27, 2023
CVE-2023-24212
9.8

CVE-2023-24212 is a critical stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code or cause denial ...

Feb 23, 2023
CVE-2021-43529
9.8

Thunderbird email client versions before 91.3.0 contain a heap overflow vulnerability when processing S/MIME messages with certificates containing DER...

Feb 16, 2023
CVE-2022-48322
9.8

A pre-authentication stack-based buffer overflow vulnerability in NETGEAR Nighthawk WiFi Mesh systems and routers allows remote attackers to execute a...

Feb 13, 2023
CVE-2023-24348
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the curTime ...

Feb 10, 2023
CVE-2023-24350
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-605L routers via a stack overflow in the email configuration functi...

Feb 10, 2023
CVE-2023-24352
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link N300 Wi-Fi Router DIR-605L devices via a stack overflow in the webpage ...

Feb 10, 2023
CVE-2022-48078
9.8

CVE-2022-48078 is a critical stack overflow vulnerability in pycdc, a Python decompiler tool. Attackers can exploit this vulnerability by providing ma...

Feb 6, 2023
CVE-2023-23088
9.8

CVE-2023-23088 is a critical buffer overflow vulnerability in Barenboim json-parser that allows remote code execution when parsing malicious JSON inpu...

Feb 3, 2023
CVE-2023-23086
9.8

CVE-2023-23086 is a critical buffer overflow vulnerability in MojoJson v1.2.3 that allows remote attackers to execute arbitrary code by exploiting the...

Feb 3, 2023
CVE-2023-25139
9.8

CVE-2023-25139 is a buffer overflow vulnerability in glibc's sprintf function that occurs when formatting numbers with thousands separators and paddin...

Feb 3, 2023
CVE-2022-48130
9.8

CVE-2022-48130 is a critical stack overflow vulnerability in Tenda W20E routers that allows remote attackers to execute arbitrary code or cause denial...

Feb 2, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,704 CVEs classified as CWE-787, with 612 rated critical and 1,879 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free