CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,702
Total CVEs
948
Critical
2,538
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 456
2 Adobe 321
3 Apple 254
4 Debian 236
5 Linux 235
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 153
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,702)

CVE-2025-1122
6.7

An out-of-bounds write vulnerability in the TPM2 reference library in ChromeOS allows attackers with root access to bypass operating system verificati...

Apr 15, 2025
CVE-2024-45780
6.7

CVE-2024-45780 is a heap buffer overflow vulnerability in grub2's tar file parser that allows integer overflow during filename buffer allocation. Atta...

Mar 3, 2025
CVE-2024-45777
6.7

This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap ...

Feb 19, 2025
CVE-2024-45781
6.7

This vulnerability in grub2 allows attackers to write beyond heap boundaries when processing symbolic links on UFS filesystems. This could lead to dat...

Feb 18, 2025
CVE-2024-45774
6.7

A buffer overflow vulnerability in GRUB2's JPEG parser allows specially crafted JPEG files to trigger an out-of-bounds write. This could potentially b...

Feb 18, 2025
CVE-2025-20636
6.7

CVE-2025-20636 is an out-of-bounds write vulnerability in secmem that allows local privilege escalation. Attackers with System privilege can exploit t...

Feb 3, 2025
CVE-2018-9405
6.7

CVE-2018-9405 is an out-of-bounds write vulnerability in Android's dm_agent component that allows local privilege escalation to System level. This aff...

Jan 18, 2025
CVE-2024-20151
6.7

CVE-2024-20151 is an out-of-bounds write vulnerability in MediaTek modem firmware that allows local privilege escalation. Attackers with initial Syste...

Jan 6, 2025
CVE-2024-20105
6.7

CVE-2024-20105 is an out-of-bounds write vulnerability in MediaTek's m4u (Memory Management Unit) driver that allows local privilege escalation. Attac...

Jan 6, 2025
CVE-2024-53836
6.7

This vulnerability allows local privilege escalation through a buffer overflow in the wbrc_bt_dev_write function of the wb_regon_coordinator.c compone...

Jan 3, 2025
CVE-2018-9386
6.7

CVE-2018-9386 is a stack buffer overflow vulnerability in the htc reboot_block driver that allows local privilege escalation. Attackers with system ex...

Dec 5, 2024
CVE-2018-9391
6.7

This vulnerability allows local privilege escalation on Android devices with MediaTek GPS chipsets. An attacker with system execution privileges can e...

Dec 5, 2024
CVE-2018-9463
6.7

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the touchscreen driver. Attackers w...

Dec 5, 2024
CVE-2018-9399
6.7

CVE-2018-9399 is a local privilege escalation vulnerability in the /proc/driver/wmt_dbg driver that allows attackers to write out of bounds memory. Th...

Dec 5, 2024
CVE-2018-9397
6.7

CVE-2018-9397 is an out-of-bounds write vulnerability in the MediaTek WMT device driver that allows local privilege escalation. Attackers with system ...

Dec 5, 2024
CVE-2018-9394
6.7

This vulnerability allows local attackers to write out-of-bounds memory in the MediaTek Wi-Fi driver, potentially leading to privilege escalation. It ...

Dec 4, 2024
CVE-2018-9392
6.7

CVE-2018-9392 is an out-of-bounds write vulnerability in the GPS hardware abstraction layer of MediaTek chipsets used in Android devices. This allows ...

Dec 4, 2024
CVE-2018-9376
6.7

CVE-2018-9376 is an out-of-bounds write vulnerability in the MediaTek ECCCI driver for Android, allowing local privilege escalation to system-level ac...

Dec 2, 2024
CVE-2024-20132
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek modem firmware that allows local privilege escalation without user interaction. At...

Dec 2, 2024
CVE-2024-20134
6.7

This CVE describes an out-of-bounds write vulnerability in the RIL (Radio Interface Layer) component of MediaTek chipsets. It allows local privilege e...

Dec 2, 2024
CVE-2024-20120
6.7

CVE-2024-20120 is an out-of-bounds write vulnerability in KeyInstall that allows local privilege escalation to System level without user interaction. ...

Nov 4, 2024
CVE-2024-20109
6.7

This CVE describes an out-of-bounds write vulnerability in the ccu component due to missing bounds checks. It allows local privilege escalation to Sys...

Nov 4, 2024
CVE-2024-20111
6.7

This vulnerability in MediaTek's ccu component allows local attackers to write beyond allocated memory boundaries, potentially leading to privilege es...

Nov 4, 2024
CVE-2024-20113
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek's ccu component that could allow local privilege escalation. Attackers with system...

Nov 4, 2024
CVE-2024-20115
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek's ccu component due to missing bounds checks. It allows local privilege escalation...

Nov 4, 2024
CVE-2024-20098
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek power management components that allows local privilege escalation. Attackers with...

Oct 7, 2024
CVE-2024-27383
6.7

A heap overflow vulnerability in Samsung Exynos mobile processors allows attackers to overwrite heap memory by sending unvalidated data to the slsi_ge...

Sep 9, 2024
CVE-2024-42642
6.7

A buffer overflow vulnerability in Micron Crucial MX500 SSDs allows attackers to execute arbitrary code on the drive controller by sending specially c...

Sep 4, 2024
CVE-2024-20087
6.7

This CVE describes an out-of-bounds write vulnerability in the vdec component of MediaTek chipsets, allowing local privilege escalation to System leve...

Sep 2, 2024
CVE-2024-27374
6.7

This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting insufficient input validation ...

Jun 5, 2024
CVE-2024-27376
6.7

This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting missing input validation in th...

Jun 5, 2024
CVE-2024-27370
6.7

This vulnerability in Samsung Exynos mobile processors allows attackers to overwrite heap memory by sending unvalidated input to the slsi_nan_config_g...

Jun 5, 2024
CVE-2024-27372
6.7

This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting lack of input validation in th...

Jun 5, 2024
CVE-2023-21071
6.7

This CVE describes a kernel-level vulnerability in Android's dhd_msgbuf.c driver where improper input validation allows an out-of-bounds write. An att...

Mar 24, 2023
CVE-2023-21073
6.7

This CVE describes a buffer overflow vulnerability in the Android kernel's dhd_rtt.c file that allows local privilege escalation. Attackers with syste...

Mar 24, 2023
CVE-2023-21076
6.7

This CVE describes a heap buffer overflow vulnerability in Android's kernel that allows local privilege escalation. Attackers can gain SYSTEM privileg...

Mar 24, 2023
CVE-2023-21078
6.7

This CVE describes a buffer overflow vulnerability in the Android kernel's rtt_unpack_xtlv_cbfn function that allows local privilege escalation. Attac...

Mar 24, 2023
CVE-2023-21050
6.7

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the PNG image loading function. Attackers wi...

Mar 24, 2023
CVE-2023-21052
6.7

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the RIL (Radio Interface Layer) component. A...

Mar 24, 2023
CVE-2023-21069
6.7

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the Wi-Fi driver. Attackers with system exec...

Mar 24, 2023
CVE-2025-11266
6.6

An out-of-bounds write vulnerability in Grassroots DICOM library (GDCM) allows attackers to cause denial-of-service by crashing applications that pars...

Dec 12, 2025
CVE-2025-48839
6.6

An authenticated attacker can execute arbitrary code on FortiADC devices by sending specially crafted HTTP requests that trigger an out-of-bounds writ...

Nov 18, 2025
CVE-2025-20963
6.6

This vulnerability allows local attackers to write out-of-bounds memory in libsavsvc.so, potentially leading to memory corruption and privilege escala...

May 7, 2025
CVE-2024-45581
6.6

This vulnerability allows memory corruption during sound model registration for voice activation in Qualcomm audio kernel drivers. Attackers could pot...

May 6, 2025
CVE-2024-45563
6.6

This vulnerability allows memory corruption in Qualcomm Camera Request Manager (CRM) when handling schedule requests due to an invalid link count in s...

May 6, 2025
CVE-2025-20642
6.6

This CVE describes an out-of-bounds write vulnerability in MediaTek DA software that could allow local privilege escalation. An attacker with physical...

Feb 3, 2025
CVE-2024-20143
6.6

This CVE describes an out-of-bounds write vulnerability in V6 DA (likely a MediaTek component) that allows local privilege escalation. Attackers with ...

Jan 6, 2025
CVE-2024-20145
6.6

This vulnerability in V6 DA allows local privilege escalation through an out-of-bounds write due to missing bounds checks. An attacker with physical a...

Jan 6, 2025
CVE-2024-20043
6.6

This CVE describes an out-of-bounds write vulnerability in MediaTek's 'da' component due to missing bounds checks. It allows local privilege escalatio...

Apr 1, 2024
CVE-2026-0665
6.5

An off-by-one error in QEMU's KVM Xen guest support allows malicious guests to trigger out-of-bounds heap accesses via the Xen physdev hypercall inter...

Feb 18, 2026

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,702 CVEs classified as CWE-787, with 948 rated critical and 2,538 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free