CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,708
Total CVEs
949
Critical
2,543
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 456
2 Adobe 325
3 Apple 254
4 Debian 238
5 Linux 235
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 153
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,708)

CVE-2024-45563
6.6

This vulnerability allows memory corruption in Qualcomm Camera Request Manager (CRM) when handling schedule requests due to an invalid link count in s...

May 6, 2025
CVE-2025-20642
6.6

This CVE describes an out-of-bounds write vulnerability in MediaTek DA software that could allow local privilege escalation. An attacker with physical...

Feb 3, 2025
CVE-2024-20143
6.6

This CVE describes an out-of-bounds write vulnerability in V6 DA (likely a MediaTek component) that allows local privilege escalation. Attackers with ...

Jan 6, 2025
CVE-2024-20145
6.6

This vulnerability in V6 DA allows local privilege escalation through an out-of-bounds write due to missing bounds checks. An attacker with physical a...

Jan 6, 2025
CVE-2024-20043
6.6

This CVE describes an out-of-bounds write vulnerability in MediaTek's 'da' component due to missing bounds checks. It allows local privilege escalatio...

Apr 1, 2024
CVE-2026-0665
6.5

An off-by-one error in QEMU's KVM Xen guest support allows malicious guests to trigger out-of-bounds heap accesses via the Xen physdev hypercall inter...

Feb 18, 2026
CVE-2026-20616
6.5

An out-of-bounds write vulnerability in USD file processing allows attackers to cause unexpected app termination or potentially execute arbitrary code...

Feb 11, 2026
CVE-2026-20404
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2, 2026
CVE-2026-20402
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. Attackers can crash affected devices by conne...

Feb 2, 2026
CVE-2026-20403
6.5

This vulnerability in MediaTek modems allows remote denial of service via system crash when a device connects to a malicious base station. Attackers c...

Feb 2, 2026
CVE-2025-68381
6.5

A buffer overflow vulnerability in Packetbeat allows remote unauthenticated attackers to crash the application or cause resource exhaustion via a sing...

Dec 18, 2025
CVE-2025-33133
6.5

This vulnerability in IBM DB2 High Performance Unload allows authenticated users to trigger an out-of-bounds write that crashes the program. It affect...

Oct 28, 2025
CVE-2024-45183
6.5

This vulnerability in Samsung Exynos mobile processors allows attackers to write data beyond allocated memory boundaries when processing JPEG images. ...

Aug 4, 2025
CVE-2025-52952
6.5

An out-of-bounds write vulnerability in Juniper Junos OS CFM daemon allows unauthenticated adjacent attackers to crash FPC cards by sending malformed ...

Jul 11, 2025
CVE-2025-22377
6.5

A heap-based out-of-bounds write vulnerability in Samsung Exynos processors' GPRS protocol implementation allows attackers to write data beyond alloca...

May 27, 2025
CVE-2025-26784
6.5

A memory corruption vulnerability in Samsung Exynos processors allows attackers to write data beyond allocated buffer boundaries due to missing length...

May 14, 2025
CVE-2024-49823
6.5

This vulnerability in IBM Common Cryptographic Architecture allows authenticated users to send specially crafted valid requests that can cause a denia...

Mar 11, 2025
CVE-2025-1938
6.5

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Mar 4, 2025
CVE-2025-1414
6.5

CVE-2025-1414 is a memory safety vulnerability in Firefox that could allow attackers to corrupt memory and potentially execute arbitrary code. This af...

Feb 18, 2025
CVE-2024-45320
6.5

An out-of-bounds write vulnerability in Fujifilm DocuPrint multifunction printers allows attackers to cause denial-of-service by sending specially cra...

Feb 18, 2025
CVE-2024-36274
6.5

An out-of-bounds write vulnerability in Intel 800 Series Ethernet drivers allows unauthenticated attackers on the same network segment to potentially ...

Feb 12, 2025
CVE-2025-0242
6.5

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Jan 7, 2025
CVE-2024-41445
6.5

CVE-2024-41445 is a heap-based buffer overread vulnerability in MDF library (mdflib) v2.1 that occurs when parsing specially crafted MDF4 files. This ...

Sep 25, 2024
CVE-2024-38533
6.5

ZKsync Era's compiler has a memory corruption vulnerability where invalid stack access can occur due to improper address-to-cell conversion. This coul...

Jun 28, 2024
CVE-2024-32760
6.5

This vulnerability in NGINX Plus and NGINX OSS allows attackers to cause denial of service by sending specially crafted HTTP/3 requests when the QUIC ...

May 29, 2024
CVE-2022-48355
6.5

This CVE describes a heap out-of-bounds read vulnerability in Huawei Bluetooth modules. Successful exploitation can cause the Bluetooth process to cra...

Mar 27, 2023
CVE-2022-2598
6.5

CVE-2022-2598 is an out-of-bounds write vulnerability in Vim's API that could allow arbitrary code execution when processing specially crafted input. ...

Aug 1, 2022
CVE-2025-20982
6.4

This vulnerability allows local privileged attackers to write out-of-bounds memory in the KnoxVault trustlet, potentially leading to memory corruption...

Jul 8, 2025
CVE-2024-49200
6.4

This vulnerability allows attackers to perform arbitrary writes in DXE memory by manipulating NVRAM variables, potentially leading to arbitrary code e...

Apr 15, 2025
CVE-2025-20943
6.4

This vulnerability allows local privileged attackers to perform out-of-bounds writes in the secfr trustlet component, leading to memory corruption. It...

Apr 8, 2025
CVE-2025-0685
6.4

This CVE describes an integer overflow vulnerability in grub2's JFS filesystem module that allows buffer overflow when reading maliciously crafted fil...

Mar 3, 2025
CVE-2025-0677
6.4

This CVE-2025-0677 vulnerability in grub2's UFS module allows heap buffer overflow when processing malicious symlinks. Attackers can exploit this to c...

Feb 19, 2025
CVE-2025-20885
6.4

This vulnerability allows local privileged attackers to perform out-of-bounds writes in the softsim trustlet, leading to memory corruption. It affects...

Feb 4, 2025
CVE-2024-49409
6.4

An out-of-bounds write vulnerability in the Battery Full Capacity node on Samsung Galaxy S24 devices allows local attackers with system privilege to w...

Nov 6, 2024
CVE-2025-43400
6.3

This CVE describes an out-of-bounds write vulnerability in font processing on Apple watchOS and tvOS. Attackers can exploit this by providing maliciou...

Sep 29, 2025
CVE-2025-21017
6.3

This vulnerability allows local privileged attackers to perform out-of-bounds memory writes in the detaching crypto box component of Blockchain Keysto...

Aug 6, 2025
CVE-2025-20900
6.3

An out-of-bounds write vulnerability in Blockchain Keystore allows local privileged attackers to write to memory beyond allocated bounds. This affects...

Feb 4, 2025
CVE-2024-54523
6.3

This vulnerability allows an app to corrupt coprocessor memory due to insufficient bounds checks. It affects macOS, watchOS, tvOS, iOS, and iPadOS dev...

Jan 27, 2025
CVE-2024-37894
6.3

Squid caching proxy versions 6.0.1 through 6.9 and 5.0.5 through 5.9 are vulnerable to memory corruption due to an out-of-bounds write error when assi...

Jun 25, 2024
CVE-2019-25485
6.2

This CVE describes a buffer overflow vulnerability in R 3.4.4 on Windows x64 systems that allows local attackers to bypass DEP and ASLR protections. B...

Mar 11, 2026
CVE-2019-25474
6.2

Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability in its unlock code validation. Local attackers can crash the application by pasti...

Mar 11, 2026
CVE-2019-25476
6.2

Outlook Password Recovery 2.10 contains a local buffer overflow vulnerability that allows attackers to crash the application by pasting oversized data...

Mar 11, 2026
CVE-2018-25198
6.2

CVE-2018-25198 is a local denial-of-service vulnerability in eToolz 3.4.8.0 where attackers can crash the application by providing oversized input buf...

Mar 6, 2026
CVE-2024-39433
6.2

This vulnerability in the drm service allows an attacker with local system execution privileges to perform an out-of-bounds write, potentially causing...

Sep 27, 2024
CVE-2021-47535
6.2

This CVE describes a memory allocation vulnerability in the Linux kernel's MSM A6xx GPU driver where insufficient memory is allocated for GMU register...

May 24, 2024
CVE-2023-52829
6.2

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's ath12k WiFi driver. An attacker could potentially write arbitrary data t...

May 21, 2024
CVE-2025-0010
6.1

This CVE describes an out-of-bounds write vulnerability in the Linux graphics driver that could allow attackers to overflow buffers and potentially ex...

Sep 6, 2025
CVE-2024-29222
6.1

This vulnerability is an out-of-bounds write in certain Intel Graphics Driver software that could allow an authenticated local user to cause a denial ...

May 13, 2025
CVE-2024-20893
6.1

This vulnerability allows local attackers to trigger memory corruption through improper input validation in Samsung's libmediaextractorservice.so libr...

Jul 2, 2024
CVE-2026-24919
6.0

This CVE describes an out-of-bounds write vulnerability in Huawei's DFX module that could allow attackers to crash affected systems, leading to denial...

Feb 6, 2026

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,708 CVEs classified as CWE-787, with 949 rated critical and 2,543 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free