CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,708
Total CVEs
949
Critical
2,543
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
105
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 456
2 Adobe 325
3 Apple 254
4 Debian 238
5 Linux 235
6 Tenda 189
7 Fedoraproject 154
8 Microsoft 153
9 Mozilla 83
10 Samsung 82

All Out-of-bounds Write CVEs (3,708)

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,708 CVEs classified as CWE-787, with 949 rated critical and 2,543 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free