CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,696)
This memory corruption vulnerability in Apple operating systems allows malicious applications to cause denial of service or potentially leak memory co...
Sep 8, 2021This is a macOS kernel memory corruption vulnerability that allows an application to cause system crashes or write to kernel memory. It affects macOS ...
Sep 8, 2021A heap buffer overflow vulnerability in Telegram's custom rlottie library allows remote attackers to potentially execute arbitrary code or crash the a...
May 18, 2021This vulnerability in the Linux kernel's KVM API allows a user process to trigger an out-of-bounds write by manipulating the internal.ndata value. It ...
May 6, 2021This vulnerability in Samsung's quram library allows attackers to overwrite arbitrary memory locations, potentially leading to arbitrary code executio...
Mar 4, 2021This vulnerability is a stack buffer overflow in Qualcomm Snapdragon chipsets that occurs when processing GSM/WCDMA broadcast configuration data. Atta...
Feb 22, 2021CVE-2017-18926 is a heap-based buffer overflow vulnerability in Raptor RDF Syntax Library's XML writer component. It allows attackers to execute arbit...
Nov 6, 2020This vulnerability allows a remote access point to trigger a heap-based buffer overflow in the Linux kernel's mwifiex wireless driver. Attackers could...
May 5, 2020CVE-2019-8545 is a memory corruption vulnerability in Apple operating systems that allows local users to cause system crashes or read kernel memory. T...
Dec 18, 2019This vulnerability allows attackers to execute arbitrary code or write arbitrary files when downloading and building Go modules with malicious version...
Jan 28, 2026This vulnerability allows local attackers to write out-of-bounds memory in the MPEG4 codec handling within libsavsvc.so on Android devices. It affects...
Jul 8, 2025This CVE describes a local privilege escalation vulnerability in MediaTek thermal management components. An attacker with System privilege can exploit...
May 5, 2025This vulnerability allows local attackers to execute arbitrary code with elevated privileges on Samsung devices by exploiting an out-of-bounds write i...
Feb 4, 2025This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...
Feb 4, 2025This vulnerability allows local attackers to execute arbitrary code with elevated privileges on affected Samsung devices by exploiting an out-of-bound...
Feb 4, 2025This vulnerability is an out-of-bounds write in libsthmbc.so video decoding library that allows local attackers to execute arbitrary code with elevate...
Feb 4, 2025This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...
May 3, 2024This CVE describes a memory access vulnerability in the Linux kernel's nct6775 hardware monitoring driver. It allows out-of-bounds read/write operatio...
Apr 3, 2024An out-of-bounds write vulnerability in Contiki-NG's IEEE 802.15.4 radio driver allows attackers to write beyond allocated buffer boundaries when pars...
Feb 14, 2024This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's TLS implementation when using splice() with ktls sockets. A local...
Jan 17, 2024This CVE describes a race condition vulnerability in the MediaTek JPEG driver for Android devices that allows local privilege escalation without user ...
Nov 6, 2023This CVE-2023-42753 is an array indexing vulnerability in the Linux kernel's netfilter subsystem that allows local attackers to perform out-of-bounds ...
Sep 25, 2023MuseScore 3.0 through 4.0.1 contains a stack buffer overflow vulnerability when processing malformed MIDI files. This allows attackers to potentially ...
Mar 28, 2023CVE-2021-3697 is a heap buffer underflow vulnerability in GRUB2's JPEG parser that allows a crafted JPEG image to corrupt heap memory. Successful expl...
Jul 6, 2022CVE-2022-26743 is an out-of-bounds write vulnerability in macOS that allows attackers who have already achieved code execution in macOS Recovery to es...
May 26, 2022CVE-2022-21882 is a Win32k elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affects...
Jan 11, 2022CVE-2020-28198 is a stack buffer overflow vulnerability in IBM Tivoli Storage Manager's administrative client (dsmadmc.exe) that allows attackers to e...
May 6, 2021CVE-2020-1477 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with user privileges. I...
Aug 17, 2020A memory management vulnerability in the Linux kernel for PowerPC systems allows unrelated processes to read/write each other's virtual memory when us...
Jun 25, 2019This is a local privilege escalation vulnerability in Windows NDIS driver where improper buffer length checking allows memory corruption. An attacker ...
May 16, 2019This CVE describes an out-of-bounds write vulnerability in DA (likely a MediaTek component) that could allow local privilege escalation. Attackers wit...
Aug 4, 2025This vulnerability in MediaTek DA software allows local attackers with physical access to escalate privileges through an out-of-bounds write. No user ...
Apr 7, 2025This CVE describes an out-of-bounds write vulnerability in MediaTek's da component that could allow local privilege escalation. Attackers with physica...
Mar 3, 2025This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by providing a specially crafted JPEG...
Feb 12, 2025This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by exploiting an out-of-bounds write ...
Feb 12, 2025This CVE describes an out-of-bounds write vulnerability in the emcom module of Huawei devices. Successful exploitation could allow attackers to corrup...
Feb 6, 2025This vulnerability in the trusty service allows local attackers with system execution privileges to perform an out-of-bounds write, potentially causin...
Jul 1, 2024This CVE describes an out-of-bounds write vulnerability in imgsys (likely MediaTek image processing subsystem) that allows local privilege escalation....
Feb 2, 2026This CVE describes an out-of-bounds write vulnerability in a display component that could allow local privilege escalation. Attackers with initial Sys...
Jan 6, 2026This CVE describes an out-of-bounds write vulnerability in a display component that could allow local privilege escalation. Attackers with initial Sys...
Jan 6, 2026This vulnerability in MediaTek wlan AP driver allows local privilege escalation through an out-of-bounds write due to incorrect bounds checking. Attac...
Nov 4, 2025This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the lwis_device_top.c component. At...
Sep 4, 2025This vulnerability in Power HAL allows local privilege escalation through an out-of-bounds write due to missing bounds checks. Attackers with System p...
Aug 4, 2025This vulnerability in Power HAL allows local privilege escalation through an out-of-bounds write due to missing bounds checks. It affects MediaTek-pow...
Aug 4, 2025An out-of-bounds write vulnerability in the TPM2 reference library in ChromeOS allows attackers with root access to bypass operating system verificati...
Apr 15, 2025CVE-2024-45780 is a heap buffer overflow vulnerability in grub2's tar file parser that allows integer overflow during filename buffer allocation. Atta...
Mar 3, 2025This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap ...
Feb 19, 2025This vulnerability in grub2 allows attackers to write beyond heap boundaries when processing symbolic links on UFS filesystems. This could lead to dat...
Feb 18, 2025A buffer overflow vulnerability in GRUB2's JPEG parser allows specially crafted JPEG files to trigger an out-of-bounds write. This could potentially b...
Feb 18, 2025CVE-2025-20636 is an out-of-bounds write vulnerability in secmem that allows local privilege escalation. Attackers with System privilege can exploit t...
Feb 3, 2025About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,696 CVEs classified as CWE-787, with 944 rated critical and 2,536 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free