CWE-787Base26 in KEV

Out-of-bounds Write

Draft in the CWE catalog · 3,204 CVEs mapped

3,204
CVEs mapped
26
In KEV
7.8
Median CVSS
What it is

The product writes data past the end, or before the beginning, of the intended buffer.

Recent examples
8.7cvss
CVE-2026-14297

The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.

A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory. The exploitable impact cannot be predetermined - it is entirely dependent on the linker-assigned BSS layout of the specific firmware build, which may vary.

HIGHno explanation yet
epss
2.3cvss
CVE-2026-81738

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

LOWno explanation yet
epss
7.8cvss
CVE-2026-86313

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

HIGHno explanation yet
epss
The record
Technical detail
CWE ID
CWE-787
Abstraction
Base
Structure
Simple
Status
Draft
References (18)