The product writes data past the end, or before the beginning, of the intended buffer.
Volume of CVEs assigned to CWE-787 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
14,355 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22457CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows | Apr 3, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-9242CRITICAL An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile Use | Sep 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2025-0282CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22. | Jan 8, 2025 | 9.0 | 98 | YES | YES |
CVE-2023-34048CRITICAL vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou | Oct 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-4911HIGH A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us | Oct 3, 2023 | 7.8 | 98 | YES | YES |
CVE-2022-42475CRITICAL A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an | Jan 2, 2023 | 9.8 | 98 | YES | YES |
CVE-2021-4034HIGH A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri | Jan 28, 2022 | 7.8 | 98 | YES | YES |
CVE-2021-20038CRITICAL A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute cod | Dec 8, 2021 | 9.8 | 98 | YES | YES |
CVE-2019-11043CRITICAL In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff | Oct 28, 2019 | 9.8 | 98 | YES | YES |
CVE-2018-0171CRITICAL A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected devi | Mar 28, 2018 | 9.8 | 98 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.