CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,933
Total CVEs
716
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 362
2 Linux 228
3 Adobe 213
4 Apple 194
5 Tenda 189
6 Debian 163
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,933)

CVE-2021-26195
8.8

CVE-2021-26195 is a heap buffer overflow vulnerability in JerryScript's number parsing function that allows attackers to execute arbitrary code or cau...

Jun 10, 2021
CVE-2021-31837
8.8

A memory corruption vulnerability in McAfee GetSusp's driver file component allows local programs to trigger a buffer overflow, potentially executing ...

Jun 9, 2021
CVE-2021-31342
8.8

This vulnerability in Solid Edge's ugeom2d.dll library allows attackers to execute arbitrary code by exploiting improper validation in DFT file parsin...

Jun 8, 2021
CVE-2021-23169
8.8

CVE-2021-23169 is a heap-buffer overflow vulnerability in OpenEXR's copyIntoFrameBuffer function that allows attackers to execute arbitrary code with ...

Jun 8, 2021
CVE-2021-30526
8.8

This vulnerability allows an attacker to perform out-of-bounds memory writes in Google Chrome's TabStrip component by convincing a user to install a m...

Jun 7, 2021
CVE-2021-30516
8.8

This CVE describes a heap buffer overflow vulnerability in Google Chrome's History component that allows a remote attacker who has already compromised...

Jun 4, 2021
CVE-2021-30518
8.8

A heap buffer overflow vulnerability in Chrome's Reader Mode allows remote attackers to potentially exploit heap corruption via a crafted HTML page. T...

Jun 4, 2021
CVE-2021-30508
8.8

This vulnerability is a heap buffer overflow in Google Chrome's Media Feeds feature that allows an attacker to potentially exploit heap corruption. At...

Jun 4, 2021
CVE-2020-24870
8.8

CVE-2020-24870 is a stack buffer overflow vulnerability in LibRaw's DNG file processing that allows remote code execution. Attackers can exploit this ...

Jun 2, 2021
CVE-2020-22036
8.8

This is a heap-based buffer overflow vulnerability in FFmpeg's filter_intra function that could allow attackers to execute arbitrary code or cause den...

Jun 1, 2021
CVE-2020-17541
8.8

CVE-2020-17541 is a stack-based buffer overflow vulnerability in libjpeg-turbo's transform component that allows remote attackers to execute arbitrary...

Jun 1, 2021
CVE-2020-22017
8.8

This heap-based buffer overflow vulnerability in FFmpeg's drawutils.c allows attackers to corrupt memory by sending specially crafted media files. It ...

May 27, 2021
CVE-2020-22023
8.8

A heap-based buffer overflow vulnerability in FFmpeg's bitplanenoise filter allows attackers to cause memory corruption by processing specially crafte...

May 27, 2021
CVE-2020-22027
8.8

A heap-based buffer overflow vulnerability in FFmpeg's neighbor filter allows attackers to execute arbitrary code or cause denial of service by proces...

May 27, 2021
CVE-2020-22034
8.8

A heap-based buffer overflow vulnerability in FFmpeg's floodfill filter allows attackers to execute arbitrary code or cause denial of service by proce...

May 27, 2021
CVE-2020-22029
8.8

This is a heap-based buffer overflow vulnerability in FFmpeg's colorconstancy filter that allows attackers to cause memory corruption by processing sp...

May 27, 2021
CVE-2020-22031
8.8

A heap-based buffer overflow vulnerability in FFmpeg's w3fdif video filter allows attackers to cause memory corruption by processing specially crafted...

May 27, 2021
CVE-2020-21831
8.8

A heap-based buffer overflow vulnerability in GNU LibreDWG 0.10 allows attackers to execute arbitrary code or cause denial of service by processing sp...

May 17, 2021
CVE-2020-21843
8.8

CVE-2020-21843 is a heap-based buffer overflow vulnerability in GNU LibreDWG 0.10, allowing attackers to execute arbitrary code or cause denial-of-ser...

May 17, 2021
CVE-2020-21830
8.8

A heap-based buffer overflow vulnerability in GNU LibreDWG 0.10 allows attackers to execute arbitrary code or cause denial of service by processing sp...

May 17, 2021
CVE-2020-21833
8.8

CVE-2020-21833 is a heap-based buffer overflow vulnerability in GNU LibreDWG's DWG file parser. Attackers can exploit this by crafting malicious DWG f...

May 17, 2021
CVE-2020-21836
8.8

CVE-2020-21836 is a heap-based buffer overflow vulnerability in GNU LibreDWG's DWG file parser. Attackers can exploit this by crafting malicious DWG f...

May 17, 2021
CVE-2020-21840
8.8

CVE-2020-21840 is a heap-based buffer overflow vulnerability in GNU LibreDWG's bit_search_sentinel function that allows attackers to execute arbitrary...

May 17, 2021
CVE-2020-21814
8.8

CVE-2020-21814 is a heap-based buffer overflow vulnerability in GNU LibreDWG's htmlwescape function that allows attackers to execute arbitrary code or...

May 17, 2021
CVE-2020-21816
8.8

CVE-2020-21816 is a heap-based buffer overflow vulnerability in GNU LibreDWG's HTML escape function that allows attackers to execute arbitrary code or...

May 17, 2021
CVE-2020-21818
8.8

A heap-based buffer overflow vulnerability in GNU LibreDWG allows attackers to execute arbitrary code or cause denial of service by processing special...

May 17, 2021
CVE-2021-31616
8.8

A stack buffer overflow vulnerability in ShapeShift KeepKey hardware wallet firmware allows remote code execution via crafted messages. Attackers can ...

May 6, 2021
CVE-2021-21227
8.8

This vulnerability in Chrome's V8 JavaScript engine allows remote attackers to potentially execute arbitrary code or cause denial of service through h...

Apr 30, 2021
CVE-2021-21220
8.8

This vulnerability in Chrome's V8 JavaScript engine allows remote attackers to potentially execute arbitrary code via heap corruption. Attackers can e...

Apr 26, 2021
CVE-2021-21225
8.8

This vulnerability allows remote attackers to exploit heap corruption in Chrome's V8 JavaScript engine through out-of-bounds memory access. Attackers ...

Apr 26, 2021
CVE-2021-31802
8.8

This vulnerability allows unauthenticated attackers on the local network to execute arbitrary code with root privileges on NETGEAR R7000 routers. It's...

Apr 26, 2021
CVE-2021-21196
8.8

This vulnerability allows a remote attacker to trigger a heap buffer overflow in Google Chrome's TabStrip component on Windows by luring users to a ma...

Apr 9, 2021
CVE-2021-23987
8.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could exploit...

Mar 31, 2021
CVE-2021-27242
8.8

This vulnerability in Parallels Desktop allows local attackers with initial low-privileged access to a guest virtual machine to escalate privileges an...

Mar 29, 2021
CVE-2021-28660
8.8

This is a buffer overflow vulnerability in the rtl8188eu Wi-Fi driver staging code in Linux kernels up to 5.11.6. It allows writing beyond the end of ...

Mar 17, 2021
CVE-2021-21192
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via heap corruption by tricking users into visiting a ...

Mar 16, 2021
CVE-2021-21169
8.8

This vulnerability allows a remote attacker to perform out-of-bounds memory access in Chrome's V8 JavaScript engine via a crafted HTML page. Attackers...

Mar 9, 2021
CVE-2021-21160
8.8

This vulnerability is a heap buffer overflow in Chrome's WebAudio component that allows remote attackers to potentially exploit heap corruption via a ...

Mar 9, 2021
CVE-2021-23964
8.8

CVE-2021-23964 is a memory corruption vulnerability in Mozilla products that could allow attackers to execute arbitrary code on affected systems. The ...

Feb 26, 2021
CVE-2021-23978
8.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Feb 26, 2021
CVE-2021-1368
8.8

A vulnerability in Cisco FXOS and NX-OS software's UDLD feature allows unauthenticated adjacent attackers to execute arbitrary code with admin privile...

Feb 24, 2021
CVE-2021-21974
8.8

CVE-2021-21974 is a heap overflow vulnerability in OpenSLP service used by VMware ESXi. It allows attackers on the same network segment to execute arb...

Feb 24, 2021
CVE-2021-21152
8.8

This vulnerability is a heap buffer overflow in Chrome's Media component on Linux systems. It allows remote attackers to potentially execute arbitrary...

Feb 22, 2021
CVE-2021-21156
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via heap corruption in Chrome's V8 JavaScript engine. ...

Feb 22, 2021
CVE-2021-0325
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices through a heap buffer overflow in the H.264 video par...

Feb 10, 2021
CVE-2021-26675
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code via a stack-based buffer overflow in ConnMan's dnsproxy component. It a...

Feb 9, 2021
CVE-2021-21144
8.8

This vulnerability is a heap buffer overflow in Chrome's Tab Groups feature that could allow an attacker to exploit heap corruption. It affects users ...

Feb 9, 2021
CVE-2020-26988
8.8

This vulnerability allows remote code execution in Siemens JT2Go and Teamcenter Visualization software. Attackers can exploit improper validation of P...

Jan 12, 2021
CVE-2020-26982
8.8

This vulnerability allows remote code execution through specially crafted CG4 and CGM files in Siemens JT2Go and Teamcenter Visualization software. At...

Jan 12, 2021
CVE-2020-26984
8.8

This vulnerability allows remote code execution through malicious JT files in Siemens JT2Go and Teamcenter Visualization software. Attackers can explo...

Jan 12, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,933 CVEs classified as CWE-787, with 716 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free