CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,933
Total CVEs
716
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 362
2 Linux 228
3 Adobe 213
4 Apple 194
5 Tenda 189
6 Debian 163
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,933)

CVE-2021-4055
8.8

This vulnerability is a heap buffer overflow in Google Chrome extensions that allows an attacker to potentially exploit heap corruption. It affects us...

Dec 23, 2021
CVE-2021-0967
8.8

This vulnerability allows an attacker to write data beyond allocated memory bounds in Android's Vorbis audio codec library. It could lead to remote in...

Dec 15, 2021
CVE-2021-0918
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android 12 ...

Dec 15, 2021
CVE-2021-43071
8.8

This vulnerability allows remote attackers to execute arbitrary code on Fortinet FortiWeb web application firewalls via specially crafted HTTP request...

Dec 9, 2021
CVE-2021-36194
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on FortiWeb web application firewalls through stack-based buffer overflows...

Dec 9, 2021
CVE-2021-43534
8.8

This CVE describes memory safety bugs in Mozilla products that could lead to memory corruption. With sufficient effort, attackers could potentially ex...

Dec 8, 2021
CVE-2021-41017
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary code or commands on affected FortiWeb devices via crafted HTTP requests....

Dec 8, 2021
CVE-2020-36129
8.8

CVE-2020-36129 is a stack buffer overflow vulnerability in AOM (AOMedia Video 1) codec library version 2.0.1 that allows attackers to execute arbitrar...

Dec 2, 2021
CVE-2020-36131
8.8

CVE-2020-36131 is a stack buffer overflow vulnerability in AOM (AOMedia Video 1) codec library version 2.0.1, specifically in the stats/rate_hist.c co...

Dec 2, 2021
CVE-2019-8922
8.8

This heap-based buffer overflow vulnerability in BlueZ's bluetoothd service allows attackers to execute arbitrary code or cause denial of service by s...

Nov 29, 2021
CVE-2021-38493
8.8

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Nov 3, 2021
CVE-2021-38495
8.8

This CVE describes memory safety bugs in Mozilla Thunderbird and Firefox ESR that could lead to memory corruption. With sufficient effort, attackers c...

Nov 3, 2021
CVE-2021-37979
8.8

This vulnerability is a heap buffer overflow in WebRTC in Google Chrome that allows remote attackers to potentially exploit heap corruption. Attackers...

Nov 2, 2021
CVE-2021-30632
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a malic...

Oct 8, 2021
CVE-2021-39531
8.8

CVE-2021-39531 is a stack-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause...

Sep 20, 2021
CVE-2021-39533
8.8

CVE-2021-39533 is a heap-based buffer overflow vulnerability in libslax's slaxLexer function that allows attackers to execute arbitrary code or cause ...

Sep 20, 2021
CVE-2021-39536
8.8

CVE-2021-39536 is a heap-based buffer overflow vulnerability in libxsmm's JIT code that allows attackers to execute arbitrary code or cause denial of ...

Sep 20, 2021
CVE-2021-32298
8.8

CVE-2021-32298 is a critical buffer overflow vulnerability in libiff's IFF_errorId function that allows remote code execution. Attackers can exploit t...

Sep 20, 2021
CVE-2021-39522
8.8

CVE-2021-39522 is a heap-based buffer overflow vulnerability in LibreDWG's bit_wcs2len() function. This allows attackers to execute arbitrary code or ...

Sep 20, 2021
CVE-2021-39525
8.8

CVE-2021-39525 is a heap-based buffer overflow vulnerability in libredwg's bit_read_fixed() function. This allows attackers to execute arbitrary code ...

Sep 20, 2021
CVE-2021-32294
8.8

CVE-2021-32294 is a heap buffer overflow vulnerability in libgig's RIFF::List::GetSubList function that allows attackers to execute arbitrary code. Th...

Sep 20, 2021
CVE-2020-21548
8.8

CVE-2020-21548 is a heap-based buffer overflow vulnerability in Libsixel's sixel_encode_highcolor function that allows attackers to execute arbitrary ...

Sep 17, 2021
CVE-2020-21598
8.8

CVE-2020-21598 is a heap buffer overflow vulnerability in libde265 v1.0.4's ff_hevc_put_unweighted_pred_8_sse function that allows remote code executi...

Sep 16, 2021
CVE-2021-30665
8.8

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....

Sep 8, 2021
CVE-2021-30799
8.8

This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into visiting malicious web content. It affe...

Sep 8, 2021
CVE-2021-30734
8.8

This CVE describes memory corruption vulnerabilities in Apple's WebKit browser engine that could allow arbitrary code execution when processing malici...

Sep 8, 2021
CVE-2021-30614
8.8

This is a heap buffer overflow vulnerability in Chromium's TabStrip component that allows attackers to execute arbitrary code or cause denial of servi...

Sep 3, 2021
CVE-2021-28564
8.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC's ImageTool component. An unauthenticated attacker can achieve arbi...

Sep 2, 2021
CVE-2021-28233
8.8

CVE-2021-28233 is a heap-based buffer overflow vulnerability in the ok-file-formats library's JPEG parsing functionality. Attackers can exploit this b...

Aug 27, 2021
CVE-2021-36530
8.8

CVE-2021-36530 is a heap buffer overflow vulnerability in ngiflib 0.4's GetByteStr() function when operating in NGIFLIB_NO_FILE mode. This allows atta...

Aug 27, 2021
CVE-2021-30592
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's Tab Groups feature. Attackers can exploit this by conv...

Aug 26, 2021
CVE-2021-30590
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via heap corruption in Google Chrome's bookmark handli...

Aug 26, 2021
CVE-2021-30851
8.8

CVE-2021-30851 is a memory corruption vulnerability in Apple's WebKit browser engine that could allow remote code execution when processing malicious ...

Aug 24, 2021
CVE-2021-28642
8.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious ...

Aug 20, 2021
CVE-2021-29990
8.8

CVE-2021-29990 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. It affects Fi...

Aug 17, 2021
CVE-2021-29984
8.8

This vulnerability involves a memory corruption flaw in Mozilla's JavaScript engine caused by instruction reordering during garbage collection. Attack...

Aug 17, 2021
CVE-2021-29976
8.8

This CVE describes memory safety bugs in Mozilla's code shared between Firefox and Thunderbird that could lead to memory corruption. With sufficient e...

Aug 5, 2021
CVE-2021-30565
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's Tab Groups feature. By convincing a user to install a ...

Aug 3, 2021
CVE-2021-30575
8.8

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to perform heap corruption via out-of-bounds write i...

Aug 3, 2021
CVE-2021-30564
8.8

This vulnerability allows remote attackers to trigger a heap buffer overflow in Chrome's WebXR implementation via a crafted HTML page. Attackers could...

Aug 3, 2021
CVE-2021-36004
8.8

CVE-2021-36004 is an out-of-bounds write vulnerability in Adobe InDesign's CoolType library that allows remote code execution when a user opens a mali...

Jul 30, 2021
CVE-2015-2100
8.8

This CVE describes multiple stack-based buffer overflows in WebGate eDVR Manager and Control Center software. Remote attackers can execute arbitrary c...

Jul 22, 2021
CVE-2021-3246
8.8

CVE-2021-3246 is a heap buffer overflow vulnerability in libsndfile's msadpcm_decode_block function that allows attackers to execute arbitrary code by...

Jul 20, 2021
CVE-2020-36428
8.8

This vulnerability in the matio library allows heap-based buffer overflow when processing specially crafted MAT files. Attackers could execute arbitra...

Jul 20, 2021
CVE-2021-0592
8.8

This vulnerability in Android's WideVine DRM component allows remote code execution through out-of-bounds writes when processing malicious media conte...

Jul 14, 2021
CVE-2020-36406
8.8

This CVE describes a stack-based buffer overflow vulnerability in uWebSockets versions 18.11.0 and 18.12.0. The vulnerability occurs in the TopicTree:...

Jul 1, 2021
CVE-2021-36082
8.8

CVE-2021-36082 is a stack-based buffer overflow vulnerability in ntop nDPI's processClientServerHello function. This allows remote attackers to execut...

Jul 1, 2021
CVE-2021-21099
8.8

Adobe InDesign versions 16.0 and earlier contain an out-of-bounds write vulnerability when parsing malicious files. An attacker can achieve remote cod...

Jun 28, 2021
CVE-2021-29966
8.8

CVE-2021-29966 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. This affects ...

Jun 24, 2021
CVE-2021-0507
8.8

This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android ver...

Jun 21, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,933 CVEs classified as CWE-787, with 716 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free