What is CWE-787?
MITRE CWEThe product writes data past the end, or before the beginning, of the intended buffer.
Verify to analyze this CWE entry
A short verification protects the official data source and prevents automated AI abuse.
The product writes data past the end, or before the beginning, of the intended buffer.
A short verification protects the official data source and prevents automated AI abuse.
The product writes data past the end, or before the beginning, of the intended buffer.
Integrity
Modify Memory, Execute Unauthorized Code or Commands
Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Availability
DoS: Crash, Exit, or Restart
Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Other
Unexpected State
Subsequent write operations can produce undefined or unexpected results.
These examples illustrate this CWE entry and are not an exhaustive list of related vulnerabilities.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
en