CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,696
Total CVEs
944
Critical
2,536
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 455
2 Adobe 321
3 Apple 254
4 Linux 235
5 Debian 233
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 152
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,696)

CVE-2021-30710
7.1

This memory corruption vulnerability in Apple operating systems allows malicious applications to cause denial of service or potentially leak memory co...

Sep 8, 2021
CVE-2021-1828
7.1

This is a macOS kernel memory corruption vulnerability that allows an application to cause system crashes or write to kernel memory. It affects macOS ...

Sep 8, 2021
CVE-2021-31320
7.1

A heap buffer overflow vulnerability in Telegram's custom rlottie library allows remote attackers to potentially execute arbitrary code or crash the a...

May 18, 2021
CVE-2021-3501
7.1

This vulnerability in the Linux kernel's KVM API allows a user process to trigger an out-of-bounds write by manipulating the internal.ndata value. It ...

May 6, 2021
CVE-2021-25346
7.1

This vulnerability in Samsung's quram library allows attackers to overwrite arbitrary memory locations, potentially leading to arbitrary code executio...

Mar 4, 2021
CVE-2020-11203
7.1

This vulnerability is a stack buffer overflow in Qualcomm Snapdragon chipsets that occurs when processing GSM/WCDMA broadcast configuration data. Atta...

Feb 22, 2021
CVE-2017-18926
7.1

CVE-2017-18926 is a heap-based buffer overflow vulnerability in Raptor RDF Syntax Library's XML writer component. It allows attackers to execute arbit...

Nov 6, 2020
CVE-2020-12654
7.1

This vulnerability allows a remote access point to trigger a heap-based buffer overflow in the Linux kernel's mwifiex wireless driver. Attackers could...

May 5, 2020
CVE-2019-8545
7.1

CVE-2019-8545 is a memory corruption vulnerability in Apple operating systems that allows local users to cause system crashes or read kernel memory. T...

Dec 18, 2019
CVE-2025-68119
7.0

This vulnerability allows attackers to execute arbitrary code or write arbitrary files when downloading and building Go modules with malicious version...

Jan 28, 2026
CVE-2025-21006
7.0

This vulnerability allows local attackers to write out-of-bounds memory in the MPEG4 codec handling within libsavsvc.so on Android devices. It affects...

Jul 8, 2025
CVE-2025-20671
7.0

This CVE describes a local privilege escalation vulnerability in MediaTek thermal management components. An attacker with System privilege can exploit...

May 5, 2025
CVE-2025-20890
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on Samsung devices by exploiting an out-of-bounds write i...

Feb 4, 2025
CVE-2025-20882
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...

Feb 4, 2025
CVE-2025-20888
7.0

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...

Feb 4, 2025
CVE-2025-20881
7.0

This vulnerability is an out-of-bounds write in libsthmbc.so video decoding library that allows local attackers to execute arbitrary code with elevate...

Feb 4, 2025
CVE-2023-34305
7.0

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...

May 3, 2024
CVE-2024-26730
7.0

This CVE describes a memory access vulnerability in the Linux kernel's nct6775 hardware monitoring driver. It allows out-of-bounds read/write operatio...

Apr 3, 2024
CVE-2023-48229
7.0

An out-of-bounds write vulnerability in Contiki-NG's IEEE 802.15.4 radio driver allows attackers to write beyond allocated buffer boundaries when pars...

Feb 14, 2024
CVE-2024-0646
7.0

This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's TLS implementation when using splice() with ktls sockets. A local...

Jan 17, 2024
CVE-2023-32832
7.0

This CVE describes a race condition vulnerability in the MediaTek JPEG driver for Android devices that allows local privilege escalation without user ...

Nov 6, 2023
CVE-2023-42753
7.0

This CVE-2023-42753 is an array indexing vulnerability in the Linux kernel's netfilter subsystem that allows local attackers to perform out-of-bounds ...

Sep 25, 2023
CVE-2023-26923
7.0

MuseScore 3.0 through 4.0.1 contains a stack buffer overflow vulnerability when processing malformed MIDI files. This allows attackers to potentially ...

Mar 28, 2023
CVE-2021-3697
7.0

CVE-2021-3697 is a heap buffer underflow vulnerability in GRUB2's JPEG parser that allows a crafted JPEG image to corrupt heap memory. Successful expl...

Jul 6, 2022
CVE-2022-26743
7.0

CVE-2022-26743 is an out-of-bounds write vulnerability in macOS that allows attackers who have already achieved code execution in macOS Recovery to es...

May 26, 2022
CVE-2022-21882
7.0

CVE-2022-21882 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affects...

Jan 11, 2022
CVE-2020-28198
7.0

CVE-2020-28198 is a stack buffer overflow vulnerability in IBM Tivoli Storage Manager's administrative client (dsmadmc.exe) that allows attackers to e...

May 6, 2021
CVE-2020-1477
7.0

CVE-2020-1477 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with user privileges. I...

Aug 17, 2020
CVE-2019-12817
7.0

A memory management vulnerability in the Linux kernel for PowerPC systems allows unrelated processes to read/write each other's virtual memory when us...

Jun 25, 2019
CVE-2019-0707
7.0

This is a local privilege escalation vulnerability in Windows NDIS driver where improper buffer length checking allows memory corruption. An attacker ...

May 16, 2019
CVE-2025-20696
6.8

This CVE describes an out-of-bounds write vulnerability in DA (likely a MediaTek component) that could allow local privilege escalation. Attackers wit...

Aug 4, 2025
CVE-2025-20656
6.8

This vulnerability in MediaTek DA software allows local attackers with physical access to escalate privileges through an out-of-bounds write. No user ...

Apr 7, 2025
CVE-2025-20650
6.8

This CVE describes an out-of-bounds write vulnerability in MediaTek's da component that could allow local privilege escalation. Attackers with physica...

Mar 3, 2025
CVE-2024-0143
6.8

This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by providing a specially crafted JPEG...

Feb 12, 2025
CVE-2024-0142
6.8

This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by exploiting an out-of-bounds write ...

Feb 12, 2025
CVE-2024-57961
6.8

This CVE describes an out-of-bounds write vulnerability in the emcom module of Huawei devices. Successful exploitation could allow attackers to corrup...

Feb 6, 2025
CVE-2024-39428
6.8

This vulnerability in the trusty service allows local attackers with system execution privileges to perform an out-of-bounds write, potentially causin...

Jul 1, 2024
CVE-2026-20410
6.7

This CVE describes an out-of-bounds write vulnerability in imgsys (likely MediaTek image processing subsystem) that allows local privilege escalation....

Feb 2, 2026
CVE-2025-20782
6.7

This CVE describes an out-of-bounds write vulnerability in a display component that could allow local privilege escalation. Attackers with initial Sys...

Jan 6, 2026
CVE-2025-20783
6.7

This CVE describes an out-of-bounds write vulnerability in a display component that could allow local privilege escalation. Attackers with initial Sys...

Jan 6, 2026
CVE-2025-20748
6.7

This vulnerability in MediaTek wlan AP driver allows local privilege escalation through an out-of-bounds write due to incorrect bounds checking. Attac...

Nov 4, 2025
CVE-2025-36908
6.7

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the lwis_device_top.c component. At...

Sep 4, 2025
CVE-2025-20698
6.7

This vulnerability in Power HAL allows local privilege escalation through an out-of-bounds write due to missing bounds checks. Attackers with System p...

Aug 4, 2025
CVE-2025-20697
6.7

This vulnerability in Power HAL allows local privilege escalation through an out-of-bounds write due to missing bounds checks. It affects MediaTek-pow...

Aug 4, 2025
CVE-2025-1122
6.7

An out-of-bounds write vulnerability in the TPM2 reference library in ChromeOS allows attackers with root access to bypass operating system verificati...

Apr 15, 2025
CVE-2024-45780
6.7

CVE-2024-45780 is a heap buffer overflow vulnerability in grub2's tar file parser that allows integer overflow during filename buffer allocation. Atta...

Mar 3, 2025
CVE-2024-45777
6.7

This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap ...

Feb 19, 2025
CVE-2024-45781
6.7

This vulnerability in grub2 allows attackers to write beyond heap boundaries when processing symbolic links on UFS filesystems. This could lead to dat...

Feb 18, 2025
CVE-2024-45774
6.7

A buffer overflow vulnerability in GRUB2's JPEG parser allows specially crafted JPEG files to trigger an out-of-bounds write. This could potentially b...

Feb 18, 2025
CVE-2025-20636
6.7

CVE-2025-20636 is an out-of-bounds write vulnerability in secmem that allows local privilege escalation. Attackers with System privilege can exploit t...

Feb 3, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,696 CVEs classified as CWE-787, with 944 rated critical and 2,536 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free