CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,933
Total CVEs
716
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 362
2 Linux 228
3 Adobe 213
4 Apple 194
5 Tenda 189
6 Debian 163
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,933)

CVE-2021-21455
8.8

CVE-2021-21455 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing D...

Jan 12, 2021
CVE-2021-21459
8.8

CVE-2021-21459 is a memory corruption vulnerability in SAP 3D Visual Enterprise Viewer version 9 caused by improper input validation when processing I...

Jan 12, 2021
CVE-2021-21461
8.8

CVE-2021-21461 is a critical vulnerability in SAP 3D Visual Enterprise Viewer version 9 that allows attackers to crash the application by tricking use...

Jan 12, 2021
CVE-2020-16028
8.8

This vulnerability allows remote attackers to trigger a heap buffer overflow in Chrome's WebRTC component via a crafted HTML page. Successful exploita...

Jan 8, 2021
CVE-2020-16013
8.8

This vulnerability in Chrome's V8 JavaScript engine allows a remote attacker to potentially cause heap corruption by tricking users into visiting a ma...

Jan 8, 2021
CVE-2020-26974
8.8

This vulnerability involves a type confusion bug in Firefox's CSS flexbox implementation where a StyleGenericFlexBasis object could be incorrectly cas...

Jan 7, 2021
CVE-2020-35114
8.8

This CVE describes memory safety bugs in Firefox that could lead to memory corruption. With sufficient effort, attackers could potentially exploit the...

Jan 7, 2021
CVE-2020-26971
8.8

This vulnerability allows attackers to trigger a heap buffer overflow by providing specially crafted blit values to video drivers. Successful exploita...

Jan 7, 2021
CVE-2020-35799
8.8

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and WiFi systems. An unauthenticated atta...

Dec 30, 2020
CVE-2020-26968
8.8

This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...

Dec 9, 2020
CVE-2020-26970
8.8

This is a stack-based buffer overflow vulnerability in Thunderbird's SMTP status code handling. An attacker could exploit this to corrupt the stack an...

Dec 9, 2020
CVE-2020-26952
8.8

This vulnerability in Firefox's JavaScript JIT compiler could allow memory corruption when handling out-of-memory conditions. An attacker could potent...

Dec 9, 2020
CVE-2017-2910
8.8

An out-of-bounds write vulnerability in libxls 2.0 allows remote code execution when processing malicious Excel files. Attackers can craft XLS files t...

Dec 2, 2020
CVE-2020-0451
8.8

This CVE describes a heap buffer overflow vulnerability in Android's SBR decoder that could allow remote code execution. Attackers could exploit this ...

Nov 10, 2020
CVE-2020-28373
8.8

This vulnerability allows remote attackers on the local network to execute arbitrary code on affected NETGEAR routers via a stack-based buffer overflo...

Nov 9, 2020
CVE-2020-16009
8.8

This vulnerability in Chrome's V8 JavaScript engine allows attackers to execute arbitrary code through heap corruption by tricking users into visiting...

Nov 3, 2020
CVE-2020-15995
8.8

This vulnerability is an out-of-bounds write in Chrome's V8 JavaScript engine that allows remote attackers to potentially exploit heap corruption via ...

Nov 3, 2020
CVE-2019-8844
8.8

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malic...

Oct 27, 2020
CVE-2019-8826
8.8

This is a memory corruption vulnerability in macOS that allows arbitrary code execution when processing malicious web content. Attackers can exploit t...

Oct 27, 2020
CVE-2019-8835
8.8

This vulnerability allows attackers to execute arbitrary code on affected Apple devices by tricking users into processing malicious web content. It af...

Oct 27, 2020
CVE-2019-8773
8.8

CVE-2019-8773 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...

Oct 27, 2020
CVE-2019-8734
8.8

CVE-2019-8734 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...

Oct 27, 2020
CVE-2019-8751
8.8

CVE-2019-8751 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...

Oct 27, 2020
CVE-2019-8728
8.8

CVE-2019-8728 is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web...

Oct 27, 2020
CVE-2019-8639
8.8

CVE-2019-8639 is a memory corruption vulnerability in Apple's WebKit browser engine that allows attackers to execute arbitrary code on affected device...

Oct 27, 2020
CVE-2020-26561
8.8

This CVE describes a stack-based buffer overflow vulnerability in Belkin LINKSYS WRT160NL routers running mini_httpd. Successful exploitation allows a...

Oct 23, 2020
CVE-2020-16158
8.8

CVE-2020-16158 is a stack-based buffer overflow vulnerability in GoPro's GPMF parser library (gpmf-parser) that allows out-of-bounds writes when parsi...

Oct 19, 2020
CVE-2020-9983
8.8

CVE-2020-9983 is an out-of-bounds write vulnerability in Safari that allows remote code execution when processing malicious web content. Attackers can...

Oct 16, 2020
CVE-2020-15667
8.8

This vulnerability allows arbitrary code execution through a heap overflow when processing malicious MAR update files with invalid name lengths. It af...

Oct 1, 2020
CVE-2020-6556
8.8

CVE-2020-6556 is a heap buffer overflow vulnerability in SwiftShader, Chrome's software renderer, that allows remote attackers to potentially execute ...

Sep 21, 2020
CVE-2020-6548
8.8

This vulnerability is a heap buffer overflow in the Skia graphics library used by Google Chrome. It allows a remote attacker who has already compromis...

Sep 21, 2020
CVE-2020-15960
8.8

This vulnerability is a heap buffer overflow in Google Chrome's storage component that allows remote attackers to potentially perform out-of-bounds me...

Sep 21, 2020
CVE-2020-0321
8.8

This vulnerability in Android's mp3 extractor allows remote code execution through an out-of-bounds write caused by uninitialized data. Attackers can ...

Sep 17, 2020
CVE-2020-0245
8.8

This CVE describes a heap buffer overflow vulnerability in Android's video decoding component that could allow remote information disclosure. Attacker...

Sep 17, 2020
CVE-2020-12248
8.8

This vulnerability allows attackers to execute arbitrary code via a heap-based buffer overflow when Foxit Reader or PhantomPDF processes malicious ima...

Sep 4, 2020
CVE-2020-3415
8.8

This vulnerability in Cisco NX-OS Software allows an unauthenticated attacker on the same network segment to execute arbitrary code with administrativ...

Aug 27, 2020
CVE-2020-15659
8.8

CVE-2020-15659 is a memory corruption vulnerability in Mozilla Firefox and Thunderbird that could allow attackers to execute arbitrary code. The vulne...

Aug 10, 2020
CVE-2020-9687
8.8

This vulnerability in Adobe Photoshop allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary code executi...

Jul 22, 2020
CVE-2020-9678
8.8

CVE-2020-9678 is an out-of-bounds write vulnerability in Adobe Prelude that allows attackers to execute arbitrary code on affected systems. This affec...

Jul 22, 2020
CVE-2020-9680
8.8

Adobe Prelude versions 9.0 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected s...

Jul 22, 2020
CVE-2020-9684
8.8

Adobe Photoshop CC 2019 and 2020 contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected systems...

Jul 22, 2020
CVE-2020-6524
8.8

This vulnerability allows a remote attacker to trigger a heap buffer overflow in Chrome's WebAudio component by tricking users into visiting a malicio...

Jul 22, 2020
CVE-2020-6530
8.8

This vulnerability allows an attacker to exploit heap corruption through out-of-bounds memory access in Chrome's developer tools. Attackers can execut...

Jul 22, 2020
CVE-2020-6533
8.8

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow a remote attacker to execute arbitrary code or cause heap cor...

Jul 22, 2020
CVE-2020-6512
8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows a remote attacker to potentially exploit heap corruption via ...

Jul 22, 2020
CVE-2020-6517
8.8

CVE-2020-6517 is a heap buffer overflow vulnerability in Google Chrome's history component that allows remote attackers to potentially execute arbitra...

Jul 22, 2020
CVE-2020-6520
8.8

This vulnerability is a buffer overflow in Skia, Chrome's graphics engine, that allows remote attackers to potentially exploit heap corruption via a c...

Jul 22, 2020
CVE-2019-20912
8.8

CVE-2019-20912 is a stack-based buffer overflow vulnerability in GNU LibreDWG's bit_read_TF function in bits.c. Attackers can exploit this by providin...

Jul 16, 2020
CVE-2020-12426
8.8

CVE-2020-12426 is a memory corruption vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulnerabi...

Jul 9, 2020
CVE-2020-6419
8.8

This vulnerability allows remote attackers to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a malic...

Jun 3, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,933 CVEs classified as CWE-787, with 716 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free