Cyber Posture

CWE · MITRE source

CWE-787Out-of-bounds Write

Abstraction: Base · CVEs in our corpus: 13,892

The product writes data past the end, or before the beginning, of the intended buffer.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SI-16Memory ProtectionSIOut-of-bounds writes that corrupt control flow or inject shellcode are rendered non-executable by the same memory protections.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-31755 KEV9.69.80.93962021-05-07
CVE-2021-20038 KEV9.69.80.94292021-12-08
CVE-2022-42475 KEV9.69.80.93982023-01-02
CVE-2023-34048 KEV9.69.80.93212023-10-25
CVE-2011-2462 KEV9.59.80.91522011-12-07
CVE-2015-3113 KEV9.59.80.92502015-06-23
CVE-2018-0171 KEV9.59.80.92672018-03-28
CVE-2019-5544 KEV9.59.80.92482019-12-06
CVE-2020-15999 KEV9.59.60.92912020-11-03
CVE-2021-35211 KEV9.59.00.94322021-07-14
CVE-2024-21762 KEV9.59.80.92682024-02-09
CVE-2018-0798 KEV9.48.80.94062018-01-10
CVE-2019-16928 KEV9.49.80.90022019-09-27
CVE-2019-11043 KEV9.48.70.94052019-10-28
CVE-2023-4863 KEV9.48.80.94082023-09-12
CVE-2025-0282 KEV9.49.00.94132025-01-08
CVE-2012-1889 KEV9.38.80.93122012-06-13
CVE-2013-3346 KEV9.39.80.89562013-08-30
CVE-2020-14871 KEV9.310.00.88872020-10-21
CVE-2021-21220 KEV9.38.80.92602021-04-26
CVE-2023-27997 KEV9.39.80.88902023-06-13
CVE-2008-2992 KEV9.27.80.93742008-11-04
CVE-2009-3953 KEV9.28.80.90512010-01-13
CVE-2010-3333 KEV9.27.80.93792010-11-10
CVE-2014-1761 KEV9.27.80.93342014-03-25