CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,710
Total CVEs
612
Critical
1,885
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,710)

CVE-2022-34601
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R200 routers via a stack overflow in the Delstlist interface. Attack...

Jul 20, 2022
CVE-2022-34603
9.8

This CVE describes a stack overflow vulnerability in H3C Magic R200 routers via the DelDNSHnList interface at /goform/aspForm. Attackers can exploit t...

Jul 20, 2022
CVE-2022-34605
9.8

CVE-2022-34605 is a critical stack overflow vulnerability in H3C Magic R200 routers that allows remote attackers to execute arbitrary code by sending ...

Jul 20, 2022
CVE-2022-34607
9.8

CVE-2022-34607 is a critical stack overflow vulnerability in H3C Magic R200 routers that allows remote attackers to execute arbitrary code by sending ...

Jul 20, 2022
CVE-2022-34609
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R200 routers via a stack overflow in the INTF parameter at /doping.a...

Jul 20, 2022
CVE-2022-34599
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R200 routers via a stack overflow in the EdittriggerList interface. ...

Jul 20, 2022
CVE-2022-20222
9.8

This critical vulnerability in Android's Bluetooth stack allows remote attackers to execute arbitrary code without user interaction. It affects Androi...

Jul 13, 2022
CVE-2022-20229
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices without user interaction. It affects Android versions...

Jul 13, 2022
CVE-2022-1737
9.8

This vulnerability in Pyramid Solutions' EtherNet/IP products allows an unauthorized attacker to send specially crafted packets causing an out-of-boun...

Jul 12, 2022
CVE-2022-33047
9.8

CVE-2022-33047 is a critical heap buffer overflow after free vulnerability in OTFCC v0.10.4 that allows attackers to execute arbitrary code or cause d...

Jul 6, 2022
CVE-2022-34835
9.8

CVE-2022-34835 is a critical stack-based buffer overflow vulnerability in Das U-Boot bootloader's 'i2c md' command. An attacker with access to the boo...

Jun 30, 2022
CVE-2022-20140
9.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices without user interaction by exploiting an out-of-bounds write ...

Jun 15, 2022
CVE-2021-40212
9.8

An out-of-bounds write vulnerability in PotPlayer version 1.7.21523 build 210729 allows attackers to write beyond allocated memory boundaries. This ca...

Jun 15, 2022
CVE-2021-30341
9.8

This vulnerability allows improper buffer size validation in DSM packets received by Qualcomm Snapdragon chipsets, leading to memory corruption. Attac...

Jun 14, 2022
CVE-2021-40036
9.8

CVE-2021-40036 is a critical memory overwrite vulnerability in the bone voice ID TA (Trusted Application) on HarmonyOS devices. Successful exploitatio...

Jun 13, 2022
CVE-2021-37404
9.8

CVE-2021-37404 is a critical heap buffer overflow vulnerability in Apache Hadoop's libhdfs native code that allows attackers to cause denial of servic...

Jun 13, 2022
CVE-2022-30914
9.8

This CVE describes a critical stack overflow vulnerability in H3C Magic R100 routers that allows remote attackers to execute arbitrary code by sending...

Jun 8, 2022
CVE-2022-30916
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R100 routers by sending specially crafted requests to the /goform/as...

Jun 8, 2022
CVE-2022-30918
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R100 routers via a stack overflow in the Asp_SetTelnet parameter. At...

Jun 8, 2022
CVE-2022-30920
9.8

This CVE describes a stack overflow vulnerability in H3C Magic R100 routers via the Edit_BasicSSID parameter at /goform/aspForm. Attackers can exploit...

Jun 8, 2022
CVE-2022-30922
9.8

This CVE describes a critical stack overflow vulnerability in H3C Magic R100 routers that allows remote attackers to execute arbitrary code via a spec...

Jun 8, 2022
CVE-2022-30924
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R100 routers via a stack overflow in the SetAPWifiorLedInfoById para...

Jun 8, 2022
CVE-2022-30926
9.8

This vulnerability allows remote attackers to execute arbitrary code on H3C Magic R100 routers via a stack overflow in the EditMacList parameter. Atta...

Jun 8, 2022
CVE-2022-30909
9.8

This CVE describes a stack overflow vulnerability in H3C Magic R100 routers via the CMD parameter at /goform/aspForm. Attackers can exploit this to ex...

Jun 8, 2022
CVE-2022-30912
9.8

This CVE describes a critical stack overflow vulnerability in H3C Magic R100 routers that allows remote attackers to execute arbitrary code by sending...

Jun 8, 2022
CVE-2022-30521
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in D-Link DIR-890L router firmware that allows unauthenticated remote code exe...

Jun 2, 2022
CVE-2022-29776
9.8

CVE-2022-29776 is a critical stack overflow vulnerability in ONLYOFFICE Document Server and Core that allows remote code execution by sending speciall...

Jun 2, 2022
CVE-2022-26723
9.8

This is a critical memory corruption vulnerability in macOS Samba client that allows arbitrary code execution when mounting a malicious Samba network ...

May 26, 2022
CVE-2022-30472
9.8

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC18 routers running firmware version 15.03.05.19(6318). Attackers ca...

May 26, 2022
CVE-2022-30474
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC Series routers via a heap overflow in the httpd module when processin...

May 26, 2022
CVE-2022-30476
9.8

This critical vulnerability in Tenda AC Series routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the http...

May 26, 2022
CVE-2022-29379
9.8

This CVE describes a stack overflow vulnerability in Nginx NJS module loader that could allow remote code execution or denial of service. However, mul...

May 25, 2022
CVE-2022-30595
9.8

CVE-2022-30595 is a critical heap buffer overflow vulnerability in Pillow's TGA image processing library. Attackers can exploit this by crafting malic...

May 25, 2022
CVE-2022-29391
9.8

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via the comment parameter in the setStaticDhcpConfi...

May 10, 2022
CVE-2022-29393
9.8

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via the comment parameter in the setIpQosRules func...

May 10, 2022
CVE-2022-29395
9.8

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote attackers to execute arbitrary code via the apcliKey parameter in ...

May 10, 2022
CVE-2022-29397
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK N600R routers by exploiting a stack overflow in the comment parameter...

May 10, 2022
CVE-2022-29399
9.8

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via a specially crafted URL parameter. Attackers ca...

May 10, 2022
CVE-2022-29322
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the DHCP configuration handler....

May 10, 2022
CVE-2022-29324
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the web interface. Attackers ca...

May 10, 2022
CVE-2022-29326
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the addhostfilter parameter. At...

May 10, 2022
CVE-2022-29328
9.8

This vulnerability is a stack-based buffer overflow in D-Link DAP-1330 firmware that allows remote attackers to execute arbitrary code via the checkva...

May 10, 2022
CVE-2022-28082
9.8

CVE-2022-28082 is a critical stack overflow vulnerability in Tenda AX12 routers that allows remote attackers to execute arbitrary code by sending spec...

May 4, 2022
CVE-2022-28560
9.8

A stack overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via crafted HTTP requests to the goform/fast_set...

May 3, 2022
CVE-2022-29077
9.8

A heap-based buffer overflow vulnerability in rippled (XRPL server software) before version 1.8.5 allows remote attackers to crash nodes or potentiall...

Apr 25, 2022
CVE-2022-27404
9.8

CVE-2022-27404 is a critical heap buffer overflow vulnerability in FreeType's sfnt_init_face function that allows attackers to execute arbitrary code ...

Apr 22, 2022
CVE-2022-28044
9.8

CVE-2022-28044 is a heap memory corruption vulnerability in lrzip's initialise_control function that allows attackers to execute arbitrary code or cau...

Apr 15, 2022
CVE-2022-26507
9.8

CVE-2022-26507 is a critical heap-based buffer overflow vulnerability in AT&T Labs Xmill 0.7's XML decompression function. It allows remote attackers ...

Apr 14, 2022
CVE-2022-27016
9.8

A stack overflow vulnerability in the SetStaticRouteCfg() function of Tenda AC9 router's httpd service allows remote code execution. This affects Tend...

Apr 7, 2022
CVE-2022-28381
9.8

CVE-2022-28381 is a critical stack-based buffer overflow vulnerability in ALLMediaServer 1.6's mediaserver.exe component. Attackers can send a special...

Apr 3, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,710 CVEs classified as CWE-787, with 612 rated critical and 1,885 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free