CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,708
Total CVEs
949
Critical
2,543
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 456
2 Adobe 325
3 Apple 254
4 Debian 238
5 Linux 235
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 153
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,708)

CVE-2025-20658
6.0

This CVE describes a permission bypass vulnerability in DA (likely a MediaTek component) that allows local privilege escalation. Attackers with physic...

Apr 7, 2025
CVE-2024-20862
6.0

This vulnerability is an out-of-bounds write in SveService on Samsung devices that allows local privileged attackers to execute arbitrary code. It aff...

May 7, 2024
CVE-2025-9903
5.9

This CVE describes an out-of-bounds write vulnerability in multiple Canon printer drivers that could allow an attacker to execute arbitrary code or ca...

Sep 29, 2025
CVE-2024-34678
5.9

This vulnerability is an out-of-bounds write in libsapeextractor.so that allows local attackers to cause memory corruption. It affects Samsung devices...

Nov 6, 2024
CVE-2024-20901
5.9

This vulnerability in libsaped allows local attackers to write out-of-bounds memory due to improper input validation when copying data to buffer cache...

Jul 2, 2024
CVE-2026-20067
5.8

This vulnerability allows unauthenticated remote attackers to cause a denial-of-service by sending crafted HTTP packets that trigger the Snort 3 detec...

Mar 4, 2026
CVE-2024-38490
5.8

CVE-2024-38490 is an out-of-bounds write vulnerability in Dell iDRAC Service Module versions 5.3.0.0 and earlier. A privileged local attacker could ex...

Aug 1, 2024
CVE-2025-21072
5.7

This vulnerability allows local privileged attackers to write out-of-bounds memory in the fingerprint trustlet during metadata decoding. It affects Sa...

Dec 2, 2025
CVE-2025-21071
5.7

This vulnerability allows local privileged attackers to write out-of-bounds memory in the fingerprint trustlet component. It affects Samsung devices w...

Nov 5, 2025
CVE-2025-60015
5.7

An out-of-bounds write vulnerability in F5OS-A and F5OS-C software could allow attackers to corrupt memory and potentially execute arbitrary code or c...

Oct 15, 2025
CVE-2025-21044
5.7

This vulnerability allows local privileged attackers to write out-of-bounds memory in the fingerprint trustlet component. It affects Samsung devices r...

Oct 10, 2025
CVE-2025-21020
5.7

This vulnerability allows local privileged attackers to write out-of-bounds memory when creating bitmap images in Blockchain Keystore. It affects syst...

Aug 6, 2025
CVE-2025-21021
5.7

This vulnerability allows local privileged attackers to write out-of-bounds memory in the drawing pinpad component of Blockchain Keystore. Attackers w...

Aug 6, 2025
CVE-2023-32472
5.7

This vulnerability allows a local authenticated user with high privileges to perform an out-of-bounds write in Dell Edge Gateway BIOS, potentially lea...

Jul 10, 2024
CVE-2023-49614
5.7

This vulnerability is an out-of-bounds write in firmware for certain Intel FPGA products, which could allow an attacker with local access to escalate ...

May 16, 2024
CVE-2021-47764
5.5

AbsoluteTelnet 11.24 contains a local denial-of-service vulnerability where attackers can crash the application by pasting specially crafted 1000-char...

Jan 15, 2026
CVE-2021-47765
5.5

AbsoluteTelnet 11.24 contains a local denial of service vulnerability where attackers can crash the application by inserting 1000+ characters into use...

Jan 15, 2026
CVE-2026-0961
5.5

A vulnerability in Wireshark's BLF file parser causes a crash when processing malicious files, leading to denial of service. This affects users runnin...

Jan 14, 2026
CVE-2025-29933
5.5

This vulnerability in AMD uProf allows a local attacker to perform out-of-bounds memory writes through improper input validation. This could lead to a...

Nov 24, 2025
CVE-2025-43380
5.5

This CVE describes an out-of-bounds write vulnerability in macOS file parsing that could allow an attacker to cause unexpected application termination...

Nov 4, 2025
CVE-2025-54275
5.5

CVE-2025-54275 is an out-of-bounds write vulnerability in Substance3D Viewer that allows attackers to cause denial-of-service by crashing the applicat...

Oct 14, 2025
CVE-2022-50553
5.5

This is an out-of-bounds write vulnerability in the Linux kernel's tracing subsystem that can cause kernel panic or potential privilege escalation. It...

Oct 7, 2025
CVE-2025-43353
5.5

This CVE describes a heap corruption vulnerability in macOS that occurs when processing maliciously crafted strings. Attackers could potentially execu...

Sep 15, 2025
CVE-2025-43302
5.5

An out-of-bounds write vulnerability in Apple operating systems allows malicious apps to write beyond allocated memory boundaries, potentially causing...

Sep 15, 2025
CVE-2025-32316
5.5

CVE-2025-32316 is an out-of-bounds write vulnerability in Android's gralloc4 memory allocator that could allow local information disclosure without re...

Sep 5, 2025
CVE-2024-58099
5.5

A memory corruption vulnerability in the Linux kernel's vmxnet3 driver allows packet corruption when using XDP (eXpress Data Path) with encapsulation ...

Apr 29, 2025
CVE-2025-30441
5.5

This vulnerability in Xcode allows malicious apps to overwrite arbitrary files on the system due to improper state management. It affects developers u...

Mar 31, 2025
CVE-2025-24185
5.5

This CVE describes an out-of-bounds write vulnerability in macOS file parsing that could allow an attacker to cause unexpected application termination...

Mar 17, 2025
CVE-2022-49557
5.5

A memory corruption vulnerability in the Linux kernel's KVM subsystem allows out-of-bounds writes when handling FPU state for virtual machines. This a...

Feb 26, 2025
CVE-2025-24122
5.5

This CVE describes a downgrade vulnerability in Intel-based Mac computers that could allow malicious applications to bypass code-signing restrictions ...

Jan 27, 2025
CVE-2024-50288
5.5

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's VIVID virtual video driver. When using more than 32 video capture buffer...

Nov 19, 2024
CVE-2024-48241
5.5

A local denial-of-service vulnerability in radare2's __bf_div function allows attackers to crash the application. This affects users running radare2 v...

Oct 30, 2024
CVE-2024-44284
5.5

CVE-2024-44284 is an out-of-bounds write vulnerability in macOS that allows parsing malicious files to cause application crashes. This affects macOS V...

Oct 28, 2024
CVE-2024-44157
5.5

A stack buffer overflow vulnerability in Apple TV and iTunes for Windows allows attackers to cause denial of service by parsing malicious video files....

Oct 11, 2024
CVE-2024-45769
5.5

This vulnerability in Performance Co-Pilot (PCP) allows attackers to send specially crafted data that could cause the program to crash or misbehave. I...

Sep 19, 2024
CVE-2024-46689
5.5

A memory mapping vulnerability in the Linux kernel's Qualcomm cmd-db driver could cause denial-of-service on affected devices. The driver incorrectly ...

Sep 13, 2024
CVE-2024-45025
5.5

A Linux kernel vulnerability in the close_range() system call with CLOSE_RANGE_UNSHARE flag can cause bitmap corruption in file descriptor tables. Thi...

Sep 11, 2024
CVE-2024-45030
5.5

A memory corruption vulnerability in the Linux kernel's igb network driver causes payload corruption during packet transmission when MAX_SKB_FRAGS is ...

Sep 11, 2024
CVE-2024-44938
5.5

This CVE-2024-44938 is a shift-out-of-bounds vulnerability in the JFS filesystem driver in the Linux kernel. It allows local attackers to trigger a ke...

Aug 26, 2024
CVE-2024-43910
5.5

A vulnerability in the Linux kernel's BPF subsystem allows attackers to pass modified CONST_PTR_TO_DYNPTR arguments to global functions, potentially l...

Aug 26, 2024
CVE-2022-48923
5.5

This CVE describes a memory corruption vulnerability in the Linux kernel's Btrfs filesystem LZO compression implementation. Attackers can trigger a bu...

Aug 22, 2024
CVE-2024-42288
5.5

This CVE describes a memory corruption vulnerability in the Linux kernel's QLogic Fibre Channel driver (qla2xxx). An incorrect dereference of the Init...

Aug 17, 2024
CVE-2024-42236
5.5

This CVE describes an out-of-bounds (OOB) read/write vulnerability in the Linux kernel's USB gadget configfs subsystem. Attackers can trigger memory c...

Aug 7, 2024
CVE-2024-40987
5.5

This CVE addresses an out-of-bounds write vulnerability in the AMD GPU driver within the Linux kernel. An attacker with local access could potentially...

Jul 12, 2024
CVE-2024-22103
5.5

An out-of-bounds write vulnerability in Jungo WinDriver allows local attackers to trigger a Windows blue screen error, causing denial of service. This...

Jul 2, 2024
CVE-2023-51778
5.5

This CVE describes an out-of-bounds write vulnerability in Jungo WinDriver that allows local attackers to trigger a Windows blue screen error, causing...

Jul 2, 2024
CVE-2024-36018
5.5

A memory corruption vulnerability in the Linux kernel's Nouveau GPU driver allows miscalculated memory remap operations to corrupt page tables, potent...

May 30, 2024
CVE-2024-35797
5.5

A Linux kernel memory management vulnerability in cachestat for shmem (shared memory) allows out-of-bounds memory access or incorrect cache statistics...

May 17, 2024
CVE-2024-4976
5.5

CVE-2024-4976 is an out-of-bounds write vulnerability in Xpdf 4.05 and earlier that allows memory corruption through malformed PDF files. Attackers ca...

May 15, 2024
CVE-2023-27754
5.5

CVE-2023-27754 is a stack buffer overflow vulnerability in vox2mesh 1.0 caused by improper use of memcpy() function. Attackers can exploit this by pro...

Mar 22, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,708 CVEs classified as CWE-787, with 949 rated critical and 2,543 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free