CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,933)
CVE-2021-21455 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing D...
Jan 12, 2021CVE-2021-21459 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing I...
Jan 12, 2021CVE-2021-21461 is a critical vulnerability in SAP 3D Visual Enterprise Viewer version 9 that allows attackers to crash the application by tricking use...
Jan 12, 2021This vulnerability allows remote attackers to trigger a heap buffer overflow in Chrome's WebRTC component via a crafted HTML page. Successful exploita...
Jan 8, 2021This vulnerability in Chrome's V8 JavaScript engine allows a remote attacker to potentially cause heap corruption by tricking users into visiting a ma...
Jan 8, 2021This vulnerability involves a type confusion bug in Firefox's CSS flexbox implementation where a StyleGenericFlexBasis object could be incorrectly cas...
Jan 7, 2021This CVE describes memory safety bugs in Firefox that could lead to memory corruption. With sufficient effort, attackers could potentially exploit the...
Jan 7, 2021This vulnerability allows attackers to trigger a heap buffer overflow by providing specially crafted blit values to video drivers. Successful exploita...
Jan 7, 2021This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and WiFi systems. An unauthenticated atta...
Dec 30, 2020This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Dec 9, 2020This is a stack-based buffer overflow vulnerability in Thunderbird's SMTP status code handling. An attacker could exploit this to corrupt the stack an...
Dec 9, 2020This vulnerability in Firefox's JavaScript JIT compiler could allow memory corruption when handling out-of-memory conditions. An attacker could potent...
Dec 9, 2020An out-of-bounds write vulnerability in libxls 2.0 allows remote code execution when processing malicious Excel files. Attackers can craft XLS files t...
Dec 2, 2020This CVE describes a heap buffer overflow vulnerability in Android's SBR decoder that could allow remote code execution. Attackers could exploit this ...
Nov 10, 2020This vulnerability allows remote attackers on the local network to execute arbitrary code on affected NETGEAR routers via a stack-based buffer overflo...
Nov 9, 2020This vulnerability in Chrome's V8 JavaScript engine allows attackers to execute arbitrary code through heap corruption by tricking users into visiting...
Nov 3, 2020This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption via ...
Nov 3, 2020This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malic...
Oct 27, 2020This is a memory corruption vulnerability in macOS that allows arbitrary code execution when processing malicious web content. Attackers can exploit t...
Oct 27, 2020This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into processing malicious web content. It af...
Oct 27, 2020CVE-2019-8773 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...
Oct 27, 2020CVE-2019-8734 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...
Oct 27, 2020CVE-2019-8751 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...
Oct 27, 2020CVE-2019-8728 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...
Oct 27, 2020CVE-2019-8639 is a memory corruption vulnerability in Apple's WebKit browser engine that allows attackers to execute arbitrary code on affected device...
Oct 27, 2020This CVE describes a stack-based buffer overflow vulnerability in Belkin LINKSYS WRT160NL routers running mini_httpd. Successful exploitation allows a...
Oct 23, 2020CVE-2020-16158 is a stack-based buffer overflow vulnerability in GoPro's GPMF parser library (gpmf-parser) that allows out-of-bounds writes when parsi...
Oct 19, 2020CVE-2020-9983 is an out-of-bounds write vulnerability in Safari that allows remote code execution when processing malicious web content. Attackers can...
Oct 16, 2020This vulnerability allows arbitrary code execution through a heap overflow when processing malicious MAR update files with invalid name lengths. It af...
Oct 1, 2020CVE-2020-6556 is a heap buffer overflow vulnerability in SwiftShader, Chrome's software renderer, that allows remote attackers to potentially execute ...
Sep 21, 2020This vulnerability is a heap buffer overflow in the Skia graphics library used by Google Chrome. It allows a remote attacker who has already compromis...
Sep 21, 2020This vulnerability is a heap buffer overflow in Google Chrome's storage component that allows remote attackers to potentially perform out-of-bounds me...
Sep 21, 2020This vulnerability in Android's mp3 extractor allows remote code execution through an out-of-bounds write caused by uninitialized data. Attackers can ...
Sep 17, 2020This CVE describes a heap buffer overflow vulnerability in Android's video decoding component that could allow remote information disclosure. Attacker...
Sep 17, 2020This vulnerability allows attackers to execute arbitrary code via a heap-based buffer overflow when Foxit Reader or PhantomPDF processes malicious ima...
Sep 4, 2020This vulnerability in Cisco NX-OS Software allows an unauthenticated attacker on the same network segment to execute arbitrary code with administrativ...
Aug 27, 2020CVE-2020-15659 is a memory corruption vulnerability in Mozilla Firefox and Thunderbird that could allow attackers to execute arbitrary code. The vulne...
Aug 10, 2020This vulnerability in Adobe Photoshop allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary code executi...
Jul 22, 2020CVE-2020-9678 is an out-of-bounds write vulnerability in Adobe Prelude that allows attackers to execute arbitrary code on affected systems. This affec...
Jul 22, 2020Adobe Prelude versions 9.0 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected s...
Jul 22, 2020Adobe Photoshop CC 2019 and 2020 contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected systems...
Jul 22, 2020This vulnerability allows a remote attacker to trigger a heap buffer overflow in Chrome's WebAudio component by tricking users into visiting a malicio...
Jul 22, 2020This vulnerability allows an attacker to exploit heap corruption through out-of-bounds memory access in Chrome's developer tools. Attackers can execut...
Jul 22, 2020This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow a remote attacker to execute arbitrary code or cause heap cor...
Jul 22, 2020This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows a remote attacker to potentially exploit heap corruption via ...
Jul 22, 2020CVE-2020-6517 is a heap buffer overflow vulnerability in Google Chrome's history component that allows remote attackers to potentially execute arbitra...
Jul 22, 2020This vulnerability is a buffer overflow in Skia, Chrome's graphics engine, that allows remote attackers to potentially exploit heap corruption via a c...
Jul 22, 2020CVE-2019-20912 is a stack-based buffer overflow vulnerability in GNU LibreDWG's bit_read_TF function in bits.c. Attackers can exploit this by providin...
Jul 16, 2020CVE-2020-12426 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulnerabi...
Jul 9, 2020This vulnerability allows remote attackers to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a malic...
Jun 3, 2020About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,933 CVEs classified as CWE-787, with 716 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free