Skip to main content

About CWE-787

Writes outside the buffer corrupt memory and can alter control data such as return addresses, which may allow code execution. Out-of-range access can also crash the product or leave it in an unexpected state.

MITRE name
Out-of-bounds Write
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft
Also known as
Memory Corruption

Mitigations

  • +Use a language that manages memory and prevents out-of-bounds writes, while watching native code interfaces.
  • +Use safer string-handling libraries such as SafeStr or Strsafe.h, recognizing many overflows do not involve strings.
  • +Double-check buffer sizes and boundary conditions in loops and copy functions.
  • +Enable compiler overflow detection and build with ASLR and PIE as defense in depth.

Detection
Automated static analysis is rated highly effective, and MITRE notes detection for buffer errors is more mature than for most weakness types. Fuzzing and runtime checkers add dynamic coverage.

CWE-787 Vulnerabilities

9 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
-7.88.8%KEV2022-03-25
CVE-2026-0300
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Palo Alto Networks9.331.7%KEV2026-05-06
CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.326.5%KEV2025-12-19
CVE-2025-9242
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.391.3%KEV2025-09-17
CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
-8.378.7%KEV2021-07-07
CVE-2024-21762
Fortinet FortiOS Out-of-Bound Write Vulnerability
Fortinet9.683.4%KEV2024-02-09
CVE-2023-26369
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild
Adobe7.86.7%KEV2023-09-13
CVE-2021-38406
Delta Electronics DOPSoft 2 Out-of-Bounds Write
Delta Electronics7.876.4%KEV2021-09-17
CVE-2021-4034
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
-7.894.3%KEV2022-01-28

Frequently Asked Questions

What is CWE-787?→

CWE-787 is an out-of-bounds write: the product writes outside the limits of the buffer it intended to use.

What is the difference between CWE-787 and CWE-119?→

CWE-119 is a broad Class covering both reads and writes outside buffer bounds and is discouraged for mapping. CWE-787 is the Base entry for writes and is one of the suggested alternatives.

How many exploited vulnerabilities are classified as CWE-787?→

This database lists 9 CVE records mapped to CWE-787 by their CVE Numbering Authority. 9 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2022-0995, CVE-2026-0300, CVE-2025-14733.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.