CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,710
Total CVEs
612
Critical
1,885
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 310
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 161
6 Debian 138
7 Fedoraproject 94
8 Samsung 77
9 Siemens 73
10 Dlink 60

All Out-of-bounds Write CVEs (2,710)

CVE-2021-43722
9.8

This vulnerability in D-Link DIR-645 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HNAP service. Attackers ca...

Mar 31, 2022
CVE-2022-23901
9.8

CVE-2022-23901 is a critical stack overflow vulnerability in re2c 2.2 caused by infinite recursion in the dead_rules.cc component. This allows remote ...

Mar 29, 2022
CVE-2022-26278
9.8

CVE-2022-26278 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code via the time par...

Mar 28, 2022
CVE-2021-38278
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10-1200 routers via a buffer overflow in the saveParentControlInfo fun...

Mar 23, 2022
CVE-2021-41736
9.8

CVE-2021-41736 is a heap-buffer overflow vulnerability in Faust's realPropagate() function that allows attackers to execute arbitrary code or cause de...

Mar 22, 2022
CVE-2022-24126
9.8

A buffer overflow vulnerability in Dark Souls III's NRSessionSearchResult parser allows remote attackers to execute arbitrary code via matchmaking ser...

Mar 20, 2022
CVE-2022-25433
9.8

CVE-2022-25433 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending speci...

Mar 18, 2022
CVE-2022-25435
9.8

CVE-2022-25435 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending speci...

Mar 18, 2022
CVE-2022-25440
9.8

CVE-2022-25440 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending speci...

Mar 18, 2022
CVE-2022-25445
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the PowerSaveSet function. Attackers...

Mar 18, 2022
CVE-2022-25447
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the openSchedWifi function. Attacker...

Mar 18, 2022
CVE-2022-25449
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by exploiting a stack overflow in the saveParentControlInfo ...

Mar 18, 2022
CVE-2022-25451
9.8

This vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack overflow in the setstaticroutecfg function. Atta...

Mar 18, 2022
CVE-2022-25453
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the saveParentControlInfo function. ...

Mar 18, 2022
CVE-2022-25455
9.8

This vulnerability is a stack overflow in Tenda AC6 routers that allows remote attackers to execute arbitrary code by sending a specially crafted requ...

Mar 18, 2022
CVE-2022-25457
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the SetSysTimeCfg function. Attacker...

Mar 18, 2022
CVE-2022-25459
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the SetSysTimeCfg function. Attacker...

Mar 18, 2022
CVE-2022-25461
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the SetPptpServerCfg function. Attac...

Mar 18, 2022
CVE-2022-25427
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers via a stack overflow in the openSchedWifi function. Attacker...

Mar 18, 2022
CVE-2022-25429
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers via a buffer overflow in the saveparentcontrolinfo function....

Mar 18, 2022
CVE-2022-22635
9.8

CVE-2022-22635 is an out-of-bounds write vulnerability in Apple's iOS, iPadOS, and tvOS that allows malicious applications to write beyond allocated m...

Mar 18, 2022
CVE-2022-22586
9.8

CVE-2022-22586 is a critical kernel privilege escalation vulnerability in macOS that allows malicious applications to execute arbitrary code with kern...

Mar 18, 2022
CVE-2022-0982
9.8

CVE-2022-0982 is a critical memory corruption vulnerability in accel-pppd's telnet component that allows remote attackers to execute arbitrary code or...

Mar 16, 2022
CVE-2022-24995
9.8

This vulnerability is a stack overflow in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can send specially crafted time paramet...

Mar 10, 2022
CVE-2022-26496
9.8

CVE-2022-26496 is a critical stack-based buffer overflow vulnerability in nbd-server (Network Block Device server) that allows remote attackers to exe...

Mar 6, 2022
CVE-2021-46393
9.8

This CVE describes a critical stack buffer overflow vulnerability in Tenda-AX3 routers that allows remote code execution. Attackers can exploit it by ...

Mar 4, 2022
CVE-2021-43086
9.8

CVE-2021-43086 is a critical buffer overflow vulnerability in ARM's astcenc 3.2.0 ASTC texture compression encoder. When using the compression functio...

Feb 28, 2022
CVE-2022-25417
9.8

CVE-2022-25417 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending speci...

Feb 24, 2022
CVE-2022-25072
9.8

This is a critical stack overflow vulnerability in TP-Link Archer A54 routers that allows unauthenticated attackers to execute arbitrary code remotely...

Feb 24, 2022
CVE-2022-25074
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on TP-Link TL-WR902AC routers due to a stack overflow in the DM_Fillobjb...

Feb 24, 2022
CVE-2021-33945
9.8

A stack buffer overflow vulnerability in RICOH printer firmware allows attackers to cause Denial of Service (DoS) by sending crafted data to the wpa_s...

Feb 15, 2022
CVE-2021-46262
9.8

A stack buffer overflow vulnerability in the PPPoE module of Tenda AC Series Router AC11 firmware allows attackers to cause Denial of Service (DoS) by...

Feb 15, 2022
CVE-2021-46264
9.8

A stack buffer overflow vulnerability in Tenda AC Series Router AC11 firmware allows attackers to cause Denial of Service (DoS) by sending specially c...

Feb 15, 2022
CVE-2021-46321
9.8

This vulnerability is a stack buffer overflow in Tenda AC Series Router AC11 firmware's wifiBasicCfg module. Attackers can send specially crafted over...

Feb 15, 2022
CVE-2021-45005
9.8

CVE-2021-45005 is a heap buffer overflow vulnerability in Artifex MuJS v1.1.3 caused by conflicting JumpList handling in nested try/finally statements...

Feb 14, 2022
CVE-2021-39675
9.8

CVE-2021-39675 is a critical heap buffer overflow vulnerability in Android's GKI_getbuf function that allows remote attackers to execute arbitrary cod...

Feb 11, 2022
CVE-2021-33913
9.8

CVE-2021-33913 is a critical heap-based buffer overflow vulnerability in libspf2 that allows remote attackers to execute arbitrary code via crafted SP...

Jan 19, 2022
CVE-2021-39623
9.8

CVE-2021-39623 is a critical memory corruption vulnerability in Android's media framework that allows remote attackers to execute arbitrary code witho...

Jan 14, 2022
CVE-2021-40010
9.8

CVE-2021-40010 is a critical heap overflow vulnerability in Huawei's bone voice ID Trusted Application (TA) component. Successful exploitation could a...

Jan 10, 2022
CVE-2021-39990
9.8

CVE-2021-39990 is a critical stack-based buffer overflow vulnerability in the screen lock module of HarmonyOS. Successful exploitation could allow att...

Jan 3, 2022
CVE-2021-45951
9.8

CVE-2021-45951 is a heap-based buffer overflow vulnerability in Dnsmasq 2.86's check_bad_address function that could allow remote code execution or de...

Jan 1, 2022
CVE-2021-45953
9.8

CVE-2021-45953 is a heap-based buffer overflow vulnerability in Dnsmasq 2.86's extract_name function that could allow remote code execution or denial ...

Jan 1, 2022
CVE-2021-45955
9.8

CVE-2021-45955 is a heap-based buffer overflow vulnerability in Dnsmasq 2.86 that occurs during DNS packet resizing due to insufficient bounds checkin...

Jan 1, 2022
CVE-2021-45957
9.8

CVE-2021-45957 is a heap-based buffer overflow vulnerability in Dnsmasq 2.86's DNS response handling code. This could allow remote attackers to execut...

Jan 1, 2022
CVE-2021-45707
9.8

This vulnerability in the nix Rust crate allows an out-of-bounds write when a user belongs to more than 16 groups in /etc/groups. Attackers could expl...

Dec 27, 2021
CVE-2018-25026
9.8

This vulnerability in the actix-web Rust crate before version 0.7.15 allows memory corruption by incorrectly marking objects as thread-safe when they ...

Dec 27, 2021
CVE-2018-25024
9.8

This vulnerability in the actix-web Rust crate allows attackers to unsoundly coerce immutable references into mutable references, leading to memory co...

Dec 27, 2021
CVE-2021-39306
9.8

A stack buffer overflow vulnerability exists in Realtek RTL8195AM devices when handling oversized authentication challenge text in WEP security mode. ...

Dec 22, 2021
CVE-2021-40394
9.8

CVE-2021-40394 is a critical out-of-bounds write vulnerability in Gerbv's RS-274X aperture macro handling that allows remote code execution via malici...

Dec 22, 2021
CVE-2021-0956
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices via NFC communication without user interaction. It af...

Dec 15, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,710 CVEs classified as CWE-787, with 612 rated critical and 1,885 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free