CWE-787: Out-of-bounds Write
Also known as: Memory Corruption
The product writes data past the end, or before the beginning, of the intended buffer.
Last updated
Overview
CWE-787 (Out-of-bounds Write) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
4,186 recorded CVEs are caused by CWE-787 (Out-of-bounds Write), including 120 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 525 new CWE-787 CVEs have been recorded so far in 2026 (582 in 2025).