CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,702)
An out-of-bounds write vulnerability in the TPM2 reference library in ChromeOS allows attackers with root access to bypass operating system verificati...
Apr 15, 2025CVE-2024-45780 is a heap buffer overflow vulnerability in grub2's tar file parser that allows integer overflow during filename buffer allocation. Atta...
Mar 3, 2025This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap ...
Feb 19, 2025This vulnerability in grub2 allows attackers to write beyond heap boundaries when processing symbolic links on UFS filesystems. This could lead to dat...
Feb 18, 2025A buffer overflow vulnerability in GRUB2's JPEG parser allows specially crafted JPEG files to trigger an out-of-bounds write. This could potentially b...
Feb 18, 2025CVE-2025-20636 is an out-of-bounds write vulnerability in secmem that allows local privilege escalation. Attackers with System privilege can exploit t...
Feb 3, 2025CVE-2018-9405 is an out-of-bounds write vulnerability in Android's dm_agent component that allows local privilege escalation to System level. This aff...
Jan 18, 2025CVE-2024-20151 is an out-of-bounds write vulnerability in MediaTek modem firmware that allows local privilege escalation. Attackers with initial Syste...
Jan 6, 2025CVE-2024-20105 is an out-of-bounds write vulnerability in MediaTek's m4u (Memory Management Unit) driver that allows local privilege escalation. Attac...
Jan 6, 2025This vulnerability allows local privilege escalation through a buffer overflow in the wbrc_bt_dev_write function of the wb_regon_coordinator.c compone...
Jan 3, 2025CVE-2018-9386 is a stack buffer overflow vulnerability in the htc reboot_block driver that allows local privilege escalation. Attackers with system ex...
Dec 5, 2024This vulnerability allows local privilege escalation on Android devices with MediaTek GPS chipsets. An attacker with system execution privileges can e...
Dec 5, 2024This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the touchscreen driver. Attackers w...
Dec 5, 2024CVE-2018-9399 is a local privilege escalation vulnerability in the /proc/driver/wmt_dbg driver that allows attackers to write out of bounds memory. Th...
Dec 5, 2024CVE-2018-9397 is an out-of-bounds write vulnerability in the MediaTek WMT device driver that allows local privilege escalation. Attackers with system ...
Dec 5, 2024This vulnerability allows local attackers to write out-of-bounds memory in the MediaTek Wi-Fi driver, potentially leading to privilege escalation. It ...
Dec 4, 2024CVE-2018-9392 is an out-of-bounds write vulnerability in the GPS hardware abstraction layer of MediaTek chipsets used in Android devices. This allows ...
Dec 4, 2024CVE-2018-9376 is an out-of-bounds write vulnerability in the MediaTek ECCCI driver for Android, allowing local privilege escalation to system-level ac...
Dec 2, 2024This CVE describes an out-of-bounds write vulnerability in MediaTek modem firmware that allows local privilege escalation without user interaction. At...
Dec 2, 2024This CVE describes an out-of-bounds write vulnerability in the RIL (Radio Interface Layer) component of MediaTek chipsets. It allows local privilege e...
Dec 2, 2024CVE-2024-20120 is an out-of-bounds write vulnerability in KeyInstall that allows local privilege escalation to System level without user interaction. ...
Nov 4, 2024This CVE describes an out-of-bounds write vulnerability in the ccu component due to missing bounds checks. It allows local privilege escalation to Sys...
Nov 4, 2024This vulnerability in MediaTek's ccu component allows local attackers to write beyond allocated memory boundaries, potentially leading to privilege es...
Nov 4, 2024This CVE describes an out-of-bounds write vulnerability in MediaTek's ccu component that could allow local privilege escalation. Attackers with system...
Nov 4, 2024This CVE describes an out-of-bounds write vulnerability in MediaTek's ccu component due to missing bounds checks. It allows local privilege escalation...
Nov 4, 2024This CVE describes an out-of-bounds write vulnerability in MediaTek power management components that allows local privilege escalation. Attackers with...
Oct 7, 2024A heap overflow vulnerability in Samsung Exynos mobile processors allows attackers to overwrite heap memory by sending unvalidated data to the slsi_ge...
Sep 9, 2024A buffer overflow vulnerability in Micron Crucial MX500 SSDs allows attackers to execute arbitrary code on the drive controller by sending specially c...
Sep 4, 2024This CVE describes an out-of-bounds write vulnerability in the vdec component of MediaTek chipsets, allowing local privilege escalation to System leve...
Sep 2, 2024This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting insufficient input validation ...
Jun 5, 2024This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting missing input validation in th...
Jun 5, 2024This vulnerability in Samsung Exynos mobile processors allows attackers to overwrite heap memory by sending unvalidated input to the slsi_nan_config_g...
Jun 5, 2024This vulnerability in Samsung Exynos mobile processors allows attackers to perform heap overwrite attacks by exploiting lack of input validation in th...
Jun 5, 2024This CVE describes a kernel-level vulnerability in Android's dhd_msgbuf.c driver where improper input validation allows an out-of-bounds write. An att...
Mar 24, 2023This CVE describes a buffer overflow vulnerability in the Android kernel's dhd_rtt.c file that allows local privilege escalation. Attackers with syste...
Mar 24, 2023This CVE describes a heap buffer overflow vulnerability in Android's kernel that allows local privilege escalation. Attackers can gain SYSTEM privileg...
Mar 24, 2023This CVE describes a buffer overflow vulnerability in the Android kernel's rtt_unpack_xtlv_cbfn function that allows local privilege escalation. Attac...
Mar 24, 2023This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the PNG image loading function. Attackers wi...
Mar 24, 2023This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the RIL (Radio Interface Layer) component. A...
Mar 24, 2023This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the Wi-Fi driver. Attackers with system exec...
Mar 24, 2023An out-of-bounds write vulnerability in Grassroots DICOM library (GDCM) allows attackers to cause denial-of-service by crashing applications that pars...
Dec 12, 2025An authenticated attacker can execute arbitrary code on FortiADC devices by sending specially crafted HTTP requests that trigger an out-of-bounds writ...
Nov 18, 2025This vulnerability allows local attackers to write out-of-bounds memory in libsavsvc.so, potentially leading to memory corruption and privilege escala...
May 7, 2025This vulnerability allows memory corruption during sound model registration for voice activation in Qualcomm audio kernel drivers. Attackers could pot...
May 6, 2025This vulnerability allows memory corruption in Qualcomm Camera Request Manager (CRM) when handling schedule requests due to an invalid link count in s...
May 6, 2025This CVE describes an out-of-bounds write vulnerability in MediaTek DA software that could allow local privilege escalation. An attacker with physical...
Feb 3, 2025This CVE describes an out-of-bounds write vulnerability in V6 DA (likely a MediaTek component) that allows local privilege escalation. Attackers with ...
Jan 6, 2025This vulnerability in V6 DA allows local privilege escalation through an out-of-bounds write due to missing bounds checks. An attacker with physical a...
Jan 6, 2025This CVE describes an out-of-bounds write vulnerability in MediaTek's 'da' component due to missing bounds checks. It allows local privilege escalatio...
Apr 1, 2024An off-by-one error in QEMU's KVM Xen guest support allows malicious guests to trigger out-of-bounds heap accesses via the Xen physdev hypercall inter...
Feb 18, 2026About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,702 CVEs classified as CWE-787, with 948 rated critical and 2,538 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free