CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
2,981 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-0300 — PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
- CVE-2025-15467 — Stack buffer overflow in CMS (Auth)EnvelopedData parsing
- CVE-2025-34105 — DiskBoss Enterprise Stack-Based Buffer Overflow RCE
- CVE-2026-3909 — Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m
- CVE-2026-79188 — Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
- CVE-2026-79131 — Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code
- CVE-2026-79043 — Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
- CVE-2026-79019 — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia
- CVE-2026-87638 — Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute ar
- CVE-2026-87621 — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentia
- CVE-2026-87438 — Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute
- CVE-2026-79189 — Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
- CVE-2026-79138 — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia
- CVE-2026-17727 — Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially
- CVE-2026-17721 — Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a
- CVE-2026-17691 — Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially
- CVE-2026-17675 — Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r
- CVE-2026-14397 — Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially per
- CVE-2026-14392 — Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a s
- CVE-2026-14152 — Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromi
Recently published
- CVE-2026-56711 — VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Overflow in Picture Allocation
- CVE-2026-87638 — Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute ar
- CVE-2026-87491 — Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in
- CVE-2026-87621 — Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentia
- CVE-2026-87438 — Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute
- CVE-2026-53938 — OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)
- CVE-2026-81980 — Acrobat Reader | Out-of-bounds Write (CWE-787)
- CVE-2026-81981 — Acrobat Reader | Out-of-bounds Write (CWE-787)
- CVE-2026-81979 — Acrobat Reader | Out-of-bounds Write (CWE-787)
- CVE-2026-81983 — Acrobat Reader | Out-of-bounds Write (CWE-787)
- CVE-2026-79908 — Acrobat Reader | Out-of-bounds Write (CWE-787)
- CVE-2026-75631 — Photoshop Desktop | Out-of-bounds Write (CWE-787)
- CVE-2026-82005 — Photoshop Desktop | Out-of-bounds Write (CWE-787)
- CVE-2026-75992 — Illustrator | Out-of-bounds Write (CWE-787)
- CVE-2026-82071 — Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write
- CVE-2026-62653 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary commu
- CVE-2026-62648 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained i
- CVE-2026-86510 — D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write
- CVE-2026-14297 — The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.
- CVE-2026-81738 — OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write