CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,789
Total CVEs
652
Critical
1,924
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
94
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 332
2 Linux 228
3 Adobe 193
4 Tenda 189
5 Apple 170
6 Debian 148
7 Fedoraproject 102
8 Samsung 77
9 Siemens 74
10 Mozilla 63

All Out-of-bounds Write CVEs (2,789)

CVE-2021-39533
8.8

CVE-2021-39533 is a heap-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause ...

Sep 20, 2021
CVE-2021-39536
8.8

CVE-2021-39536 is a heap-based buffer overflow vulnerability in libxsmm's JIT code that allows attackers to execute arbitrary code or cause denial of ...

Sep 20, 2021
CVE-2021-32298
8.8

CVE-2021-32298 is a critical buffer overflow vulnerability in libiff's IFF_errorId function that allows remote code execution. Attackers can exploit t...

Sep 20, 2021
CVE-2021-39522
8.8

CVE-2021-39522 is a heap-based buffer overflow vulnerability in LibreDWG's bit_wcs2len() function. This allows attackers to execute arbitrary code or ...

Sep 20, 2021
CVE-2021-39525
8.8

CVE-2021-39525 is a heap-based buffer overflow vulnerability in libredwg's bit_read_fixed() function. This allows attackers to execute arbitrary code ...

Sep 20, 2021
CVE-2021-32294
8.8

CVE-2021-32294 is a heap buffer overflow vulnerability in libgig's RIFF::List::GetSubList function that allows attackers to execute arbitrary code. Th...

Sep 20, 2021
CVE-2020-21548
8.8

CVE-2020-21548 is a heap-based buffer overflow vulnerability in Libsixel's sixel_encode_highcolor function that allows attackers to execute arbitrary ...

Sep 17, 2021
CVE-2020-21598
8.8

CVE-2020-21598 is a heap buffer overflow vulnerability in libde265 v1.0.4's ff_hevc_put_unweighted_pred_8_sse function that allows remote code executi...

Sep 16, 2021
CVE-2021-30665
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....

Sep 8, 2021
CVE-2021-30799
8.8

This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into visiting malicious web content. It affe...

Sep 8, 2021
CVE-2021-30734
8.8

This CVE describes memory corruption vulnerabilities in Apple's WebKit browser engine that could allow arbitrary code execution when processing malici...

Sep 8, 2021
CVE-2021-30614
8.8

This is a heap buffer overflow vulnerability in Chromium's TabStrip component that allows attackers to execute arbitrary code or cause denial of servi...

Sep 3, 2021
CVE-2021-28564
8.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC's ImageTool component. An unauthenticated attacker can achieve arbi...

Sep 2, 2021
CVE-2021-28233
8.8

CVE-2021-28233 is a heap-based buffer overflow vulnerability in the ok-file-formats library's JPEG parsing functionality. Attackers can exploit this b...

Aug 27, 2021
CVE-2021-36530
8.8

CVE-2021-36530 is a heap buffer overflow vulnerability in ngiflib 0.4's GetByteStr() function when operating in NGIFLIB_NO_FILE mode. This allows atta...

Aug 27, 2021
CVE-2021-30592
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's Tab Groups feature. Attackers can exploit this by conv...

Aug 26, 2021
CVE-2021-30590
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via heap corruption in Google Chrome's bookmark handli...

Aug 26, 2021
CVE-2021-30851
8.8

CVE-2021-30851 is a memory corruption vulnerability in Apple's WebKit browser engine that could allow remote code execution when processing malicious ...

Aug 24, 2021
CVE-2021-28642
8.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious ...

Aug 20, 2021
CVE-2021-29990
8.8

CVE-2021-29990 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. It affects Fi...

Aug 17, 2021
CVE-2021-29984
8.8

This vulnerability involves a memory corruption flaw in Mozilla's JavaScript engine caused by instruction reordering during garbage collection. Attack...

Aug 17, 2021
CVE-2021-29976
8.8

This CVE describes memory safety bugs in Mozilla's code shared between Firefox and Thunderbird that could lead to memory corruption. With sufficient e...

Aug 5, 2021
CVE-2021-30565
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's Tab Groups feature. By convincing a user to install a ...

Aug 3, 2021
CVE-2021-30575
8.8

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to perform heap corruption via out-of-bounds write i...

Aug 3, 2021
CVE-2021-30564
8.8

This vulnerability allows remote attackers to trigger a heap buffer overflow in Chrome's WebXR implementation via a crafted HTML page. Attackers could...

Aug 3, 2021
CVE-2021-36004
8.8

CVE-2021-36004 is an out-of-bounds write vulnerability in Adobe InDesign's CoolType library that allows remote code execution when a user opens a mali...

Jul 30, 2021
CVE-2015-2100
8.8

This CVE describes multiple stack-based buffer overflows in WebGate eDVR Manager and Control Center software. Remote attackers can execute arbitrary c...

Jul 22, 2021
CVE-2021-3246
8.8

CVE-2021-3246 is a heap buffer overflow vulnerability in libsndfile's msadpcm_decode_block function that allows attackers to execute arbitrary code by...

Jul 20, 2021
CVE-2020-36428
8.8

This vulnerability in the matio library allows heap-based buffer overflow when processing specially crafted MAT files. Attackers could execute arbitra...

Jul 20, 2021
CVE-2021-0592
8.8

This vulnerability in Android's WideVine DRM component allows remote code execution through out-of-bounds writes when processing malicious media conte...

Jul 14, 2021
CVE-2020-36406
8.8

This CVE describes a stack-based buffer overflow vulnerability in uWebSockets versions 18.11.0 and 18.12.0. The vulnerability occurs in the TopicTree:...

Jul 1, 2021
CVE-2021-36082
8.8

CVE-2021-36082 is a stack-based buffer overflow vulnerability in ntop nDPI's processClientServerHello function. This allows remote attackers to execut...

Jul 1, 2021
CVE-2021-21099
8.8

Adobe InDesign versions 16.0 and earlier contain an out-of-bounds write vulnerability when parsing malicious files. An attacker can achieve remote cod...

Jun 28, 2021
CVE-2021-29966
8.8

CVE-2021-29966 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. This affects ...

Jun 24, 2021
CVE-2021-0507
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android ver...

Jun 21, 2021
CVE-2021-26195
8.8

CVE-2021-26195 is a heap buffer overflow vulnerability in JerryScript's number parsing function that allows attackers to execute arbitrary code or cau...

Jun 10, 2021
CVE-2021-31837
8.8

A memory corruption vulnerability in McAfee GetSusp's driver file component allows local programs to trigger a buffer overflow, potentially executing ...

Jun 9, 2021
CVE-2021-31342
8.8

This vulnerability in Solid Edge's ugeom2d.dll library allows attackers to execute arbitrary code by exploiting improper validation in DFT file parsin...

Jun 8, 2021
CVE-2021-23169
8.8

CVE-2021-23169 is a heap-buffer overflow vulnerability in OpenEXR's copyIntoFrameBuffer function that allows attackers to execute arbitrary code with ...

Jun 8, 2021
CVE-2021-30526
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's TabStrip component by convincing a user to install a m...

Jun 7, 2021
CVE-2021-30516
8.8

This CVE describes a heap buffer overflow vulnerability in Google Chrome's History component that allows a remote attacker who has already compromised...

Jun 4, 2021
CVE-2021-30518
8.8

A heap buffer overflow vulnerability in Chrome's Reader Mode allows remote attackers to potentially exploit heap corruption via a crafted HTML page. T...

Jun 4, 2021
CVE-2021-30508
8.8

This vulnerability is a heap buffer overflow in Google Chrome's Media Feeds feature that allows an attacker to potentially exploit heap corruption. At...

Jun 4, 2021
CVE-2020-24870
8.8

CVE-2020-24870 is a stack buffer overflow vulnerability in LibRaw's DNG file processing that allows remote code execution. Attackers can exploit this ...

Jun 2, 2021
CVE-2020-22036
8.8

This is a heap-based buffer overflow vulnerability in FFmpeg's filter_intra function that could allow attackers to execute arbitrary code or cause den...

Jun 1, 2021
CVE-2020-17541
8.8

CVE-2020-17541 is a stack-based buffer overflow vulnerability in libjpeg-turbo's transform component that allows remote attackers to execute arbitrary...

Jun 1, 2021
CVE-2020-22017
8.8

This heap-based buffer overflow vulnerability in FFmpeg's drawutils.c allows attackers to corrupt memory by sending specially crafted media files. It ...

May 27, 2021
CVE-2020-22023
8.8

A heap-based buffer overflow vulnerability in FFmpeg's bitplanenoise filter allows attackers to cause memory corruption by processing specially crafte...

May 27, 2021
CVE-2020-22027
8.8

A heap-based buffer overflow vulnerability in FFmpeg's neighbor filter allows attackers to execute arbitrary code or cause denial of service by proces...

May 27, 2021
CVE-2020-22034
8.8

A heap-based buffer overflow vulnerability in FFmpeg's floodfill filter allows attackers to execute arbitrary code or cause denial of service by proce...

May 27, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,789 CVEs classified as CWE-787, with 652 rated critical and 1,924 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free