CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,708
Total CVEs
949
Critical
2,543
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 456
2 Adobe 325
3 Apple 254
4 Debian 238
5 Linux 235
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 153
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,708)

CVE-2020-1379
5.5

CVE-2020-1379 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with user privileges. I...

Aug 17, 2020
CVE-2026-1489
5.4

An integer overflow vulnerability in GLib's Unicode case conversion implementation allows memory corruption when processing extremely large Unicode st...

Jan 27, 2026
CVE-2026-20417
5.3

This CVE describes an out-of-bounds write vulnerability in PCIe drivers that could allow local privilege escalation. Attackers with initial System pri...

Feb 2, 2026
CVE-2026-0962
5.3

A vulnerability in Wireshark's SOME/IP-SD protocol dissector causes crashes when processing malicious packets, leading to denial of service. This affe...

Jan 14, 2026
CVE-2026-0959
5.3

A vulnerability in Wireshark's IEEE 802.11 protocol dissector causes crashes when processing specially crafted wireless network packets. This affects ...

Jan 14, 2026
CVE-2025-60661
5.3

A stack overflow vulnerability in Tenda AC18 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafte...

Oct 2, 2025
CVE-2025-46152
5.3

A vulnerability in PyTorch's bitwise_right_shift function produces incorrect output when given out-of-bounds values for the 'other' argument. This cou...

Sep 25, 2025
CVE-2025-48499
5.3

An out-of-bounds write vulnerability in FUJIFILM Business Innovation MFPs allows attackers to cause a denial-of-service condition by sending specially...

Aug 4, 2025
CVE-2025-41679
5.3

An unauthenticated remote attacker can exploit a buffer overflow vulnerability in the Conftool network initialization wizard service, causing denial o...

Jul 21, 2025
CVE-2025-0235
5.3

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting an out-of-bounds write during image rendering i...

Feb 26, 2025
CVE-2025-20889
5.3

This vulnerability allows local attackers to read arbitrary memory by exploiting an out-of-bounds read in the smp4vtd bitstream decoder in libsthmbc.s...

Feb 4, 2025
CVE-2024-45185
5.1

This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Samsung Exynos processors due to a heap overflow ...

Nov 4, 2024
CVE-2024-9482
5.1

An out-of-bounds write vulnerability in AVG/Avast Antivirus for macOS allows a specially crafted Mach-O file to crash the antivirus application during...

Oct 4, 2024
CVE-2024-39430
5.1

This vulnerability in the faceid service allows local attackers to cause denial of service through an out-of-bounds write. It affects Unisoc devices w...

Jul 1, 2024
CVE-2020-1483
5.0

This is a remote code execution vulnerability in Microsoft Outlook where specially crafted files can trigger memory handling errors, allowing attacker...

Aug 17, 2020
CVE-2024-52755
4.9

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a buffer overflow in the host_ip parameter of the ...

Nov 21, 2024
CVE-2024-52757
4.9

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a buffer overflow in the D-LINK DI-8003 router's A...

Nov 20, 2024
CVE-2024-33008
4.9

This vulnerability in SAP Replication Server allows attackers to execute commands through a gateway to RSSD, potentially causing memory corruption tha...

May 14, 2024
CVE-2025-32404
4.8

An out-of-bounds write vulnerability in RT-Labs P-Net library allows attackers to corrupt memory in IO devices by sending malicious RPC packets. This ...

May 7, 2025
CVE-2024-25948
4.8

CVE-2024-25948 is an out-of-bounds write vulnerability in Dell iDRAC Service Module versions 5.3.0.0 and earlier. A privileged local attacker could ex...

Aug 1, 2024
CVE-2025-68160
4.7

This vulnerability in OpenSSL's line-buffering BIO filter allows heap-based out-of-bounds writes when processing large, newline-free data with short w...

Jan 27, 2026
CVE-2024-28970
4.7

Dell Client BIOS contains an out-of-bounds write vulnerability that allows a local authenticated malicious user with admin privileges to potentially c...

Jun 12, 2024
CVE-2025-4877
4.5

A heap corruption vulnerability in 32-bit builds of libssh occurs when ssh_get_fingerprint_hash() receives an unexpectedly large input buffer, causing...

Aug 20, 2025
CVE-2024-34776
4.5

An out-of-bounds write vulnerability in Intel SGX SDK software allows authenticated local users to potentially escalate privileges. This affects syste...

Nov 13, 2024
CVE-2024-34676
4.4

An out-of-bounds write vulnerability in libsubextractor.so subtitle parsing library allows local attackers to cause memory corruption when processing ...

Nov 6, 2024
CVE-2024-0110
4.4

The NVIDIA CUDA Toolkit's cuobjdump utility contains an out-of-bounds write vulnerability when processing malformed ELF files. This could allow attack...

Aug 31, 2024
CVE-2023-21046
4.4

This vulnerability allows local information disclosure on Android devices through an out-of-bounds read in the ConvertToHalMetadata function. Attacker...

Mar 24, 2023
CVE-2023-20956
4.4

This CVE describes an out-of-bounds write vulnerability in Android's C2SurfaceSyncObj.cpp import function due to missing bounds checks. It could allow...

Mar 24, 2023
CVE-2025-43501
4.3

A buffer overflow vulnerability in Apple's Safari browser and related operating systems allows attackers to cause unexpected process crashes by tricki...

Dec 17, 2025
CVE-2025-58477
4.3

This vulnerability allows remote attackers to write outside the bounds of allocated memory when parsing IFD tags in libimagecodec.quram.so, potentiall...

Dec 2, 2025
CVE-2025-58478
4.3

This vulnerability allows remote attackers to write data outside the intended memory boundaries in Samsung's libimagecodec.quram.so library. It affect...

Dec 2, 2025
CVE-2025-58480
4.3

A heap-based buffer overflow vulnerability in Samsung's libimagecodec.quram.so library allows remote attackers to access out-of-bounds memory. This af...

Dec 2, 2025
CVE-2025-64406
4.3

An out-of-bounds write vulnerability in Apache OpenOffice allows attackers to craft malicious documents that could crash the program or corrupt memory...

Nov 12, 2025
CVE-2025-21075
4.3

This vulnerability is an out-of-bounds write in Samsung's libimagecodec.quram.so library that allows remote attackers to access out-of-bounds memory. ...

Nov 5, 2025
CVE-2025-0143
4.3

An out-of-bounds write vulnerability in Zoom Workplace App for Linux allows unauthorized attackers to cause denial of service via network access. This...

Jan 30, 2025
CVE-2026-1484
4.2

A buffer overflow vulnerability exists in GLib's Base64 encoding routine when processing extremely large input data due to integer type miscalculation...

Jan 27, 2026
CVE-2025-23275
4.2

This vulnerability in NVIDIA CUDA Toolkit's nvJPEG component allows a local authenticated user to trigger a GPU out-of-bounds write by providing speci...

Sep 24, 2025
CVE-2020-1180
4.2

This is a remote code execution vulnerability in the ChakraCore JavaScript engine that allows attackers to execute arbitrary code with the privileges ...

Sep 11, 2020
CVE-2020-0878
4.2

This is a memory corruption vulnerability in Microsoft browsers that allows remote code execution. Attackers can exploit it by tricking users into vis...

Sep 11, 2020
CVE-2019-1196
4.2

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by tricking...

Aug 14, 2019
CVE-2019-1131
4.2

CVE-2019-1131 is a memory corruption vulnerability in Microsoft Edge's Chakra JavaScript engine that allows remote code execution. Attackers can explo...

Aug 14, 2019
CVE-2025-64503
4.0

CVE-2025-64503 is an integer overflow vulnerability in cups-filters' pdftoraster tool that can lead to out-of-bounds memory writes when processing mal...

Nov 12, 2025
CVE-2025-21070
4.0

This vulnerability allows local attackers to perform out-of-bounds memory writes in Samsung Notes' SPI decoder. It affects users of Samsung Notes vers...

Oct 10, 2025
CVE-2025-21052
4.0

This vulnerability allows local attackers to cause memory corruption through an out-of-bounds write during JPEG decoding in libpadm.so. It affects Sam...

Oct 10, 2025
CVE-2025-21053
4.0

This vulnerability allows local attackers to trigger memory corruption through an out-of-bounds write in the JPEG header parsing functionality of libp...

Oct 10, 2025
CVE-2024-49739
4.0

This vulnerability in Android's memory management allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated pri...

Sep 4, 2025
CVE-2025-21034
4.0

This vulnerability allows local attackers to perform out-of-bounds writes in libsavsvc.so, potentially leading to arbitrary code execution. It affects...

Sep 3, 2025
CVE-2025-54616
4.0

This CVE describes an out-of-bounds array access vulnerability in Huawei's ArkUI framework. Successful exploitation could cause application crashes or...

Aug 6, 2025
CVE-2025-11964
1.9

A buffer overflow vulnerability exists in libpcap on Windows when converting certain Windows error messages to UTF-8. This could allow an attacker to ...

Dec 31, 2025
CVE-2026-1301
N/A

This vulnerability allows an attacker to send a specially crafted JSON message to systems with PubSub and JSON enabled, causing a heap buffer overflow...

Feb 5, 2026

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,708 CVEs classified as CWE-787, with 949 rated critical and 2,543 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free