CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,947
Total CVEs
730
Critical
2,004
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 363
2 Linux 228
3 Adobe 217
4 Apple 194
5 Tenda 189
6 Debian 165
7 Fedoraproject 116
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,947)

CVE-2023-42443
8.1

This vulnerability in Vyper smart contract language allows memory corruption when using specific builtin functions with complex expressions, potential...

Sep 18, 2023
CVE-2023-3633
8.1

An out-of-bounds write vulnerability in Bitdefender Engines on Windows allows memory corruption that can crash the engine. This affects Bitdefender pr...

Jul 14, 2023
CVE-2023-20894
8.1

This vulnerability allows attackers with network access to VMware vCenter Server to send specially crafted DCERPC packets causing memory corruption th...

Jun 22, 2023
CVE-2023-20892
8.1

This CVE describes a heap overflow vulnerability in vCenter Server's DCERPC protocol implementation due to uninitialized memory usage. Attackers with ...

Jun 22, 2023
CVE-2022-23677
8.1

This CVE allows remote attackers to execute arbitrary code on affected ArubaOS-Switch devices, potentially leading to complete system compromise. It a...

May 10, 2022
CVE-2021-41987
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Mikrotik RouterOS devices by exploiting a heap-based buffer overflow ...

Mar 16, 2022
CVE-2021-38684
8.1

A stack buffer overflow vulnerability in QNAP NAS Multimedia Console allows attackers to execute arbitrary code on affected systems. This affects QNAP...

Nov 13, 2021
CVE-2021-30717
8.1

This memory corruption vulnerability in macOS allows attackers in a privileged network position to execute arbitrary code on affected systems. It affe...

Sep 8, 2021
CVE-2021-29630
8.1

This is a stack-based buffer overflow vulnerability in FreeBSD's ggatec daemon that allows remote code execution. Attackers in a privileged network po...

Aug 30, 2021
CVE-2021-26221
8.1

CVE-2021-26221 is an out-of-bounds write vulnerability in ezXML's ezxml_new function that occurs when processing XML files after memory pool exhaustio...

Feb 8, 2021
CVE-2020-15212
8.1

This vulnerability in TensorFlow Lite allows attackers with access to segment_ids_data to trigger out-of-bounds writes to heap-allocated buffers by in...

Sep 25, 2020
CVE-2020-15214
8.1

This vulnerability in TensorFlow Lite allows memory corruption when processing models with unsorted segment IDs in segment sum operations. It affects ...

Sep 25, 2020
CVE-2020-1912
8.1

CVE-2020-1912 is an out-of-bounds read/write vulnerability in Facebook's Hermes JavaScript engine that could allow attackers to execute arbitrary code...

Sep 9, 2020
CVE-2023-21475
8.0

This vulnerability allows a local attacker to write data beyond allocated memory boundaries in Samsung's libaudiosaplus_sec.so library, potentially le...

Sep 3, 2025
CVE-2023-34551
8.0

This vulnerability allows an authenticated attacker on the same local network as affected EZVIZ security cameras to execute arbitrary code via stack b...

Aug 1, 2023
CVE-2022-48330
8.0

This CVE describes an out-of-bounds write vulnerability in Huawei FLMG-10 sound box products. Attackers can exploit this buffer overflow vulnerability...

Jun 16, 2023
CVE-2020-27301
8.0

A stack buffer overflow vulnerability in Realtek RTL8710 and other Ameba-based WiFi chips allows remote code execution. Attackers within Wi-Fi range c...

Jun 4, 2021
CVE-2021-3182
8.0

CVE-2021-3182 is a buffer overflow vulnerability in D-Link DCS-5220 security cameras that allows remote attackers to execute arbitrary code or cause d...

Jan 19, 2021
CVE-2020-9395
8.0

A stack-based buffer overflow vulnerability exists in Realtek Wi-Fi chipset firmware for specific IoT devices. Attackers can exploit this by sending a...

Jul 6, 2020
CVE-2021-26383
7.9

CVE-2021-26383 is a memory corruption vulnerability in AMD's Trusted Execution Environment (TEE) where insufficient bounds checking allows attackers w...

Sep 6, 2025
CVE-2024-22254
7.9

This CVE describes an out-of-bounds write vulnerability in VMware ESXi that could allow a malicious actor with VMX process privileges to escape the sa...

Mar 5, 2024
CVE-2024-20027
7.9

This CVE describes an out-of-bounds write vulnerability in MediaTek's 'da' component due to improper input validation. It allows local privilege escal...

Mar 4, 2024
CVE-2023-22442
7.9

An out-of-bounds write vulnerability in Intel Server Board BMC firmware allows privileged users with local access to escalate privileges. This affects...

May 10, 2023
CVE-2021-34373
7.9

This vulnerability in NVIDIA's Trusty trusted Linux kernel (TLK) allows heap overflows due to insufficient heap hardening. Attackers could exploit thi...

Jun 30, 2021
CVE-2026-3094
7.8

Delta Electronics CNCSoft-G2 has a file parsing vulnerability that allows out-of-bounds write when processing malicious files. This enables remote cod...

Mar 4, 2026
CVE-2025-47373
7.8

This CVE describes a memory corruption vulnerability in Qualcomm Trusted Application (TA) invocation where accessing buffers with invalid length can l...

Mar 2, 2026
CVE-2026-0874
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPART files in affected Autodesk products. Us...

Feb 18, 2026
CVE-2026-1335
7.8

An Out-Of-Bounds Write vulnerability in SOLIDWORKS eDrawings allows an attacker to execute arbitrary code by tricking a user into opening a malicious ...

Feb 16, 2026
CVE-2026-21349
7.8

Lightroom Desktop versions 15.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when use...

Feb 10, 2026
CVE-2026-21352
7.8

CVE-2026-21352 is an out-of-bounds write vulnerability in Adobe DNG SDK versions 1.7.1 2410 and earlier that could allow arbitrary code execution when...

Feb 10, 2026
CVE-2026-21346
7.8

CVE-2026-21346 is an out-of-bounds write vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious file. T...

Feb 10, 2026
CVE-2026-21341
7.8

CVE-2026-21341 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...

Feb 10, 2026
CVE-2026-21335
7.8

Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a...

Feb 10, 2026
CVE-2026-21328
7.8

Adobe After Effects versions 25.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a v...

Feb 10, 2026
CVE-2026-21318
7.8

CVE-2026-21318 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Feb 10, 2026
CVE-2026-21312
7.8

Adobe Audition versions 25.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a user...

Feb 10, 2026
CVE-2026-23715
7.8

An out-of-bounds write vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into openin...

Feb 10, 2026
CVE-2026-0536
7.8

A stack-based buffer overflow vulnerability in Autodesk 3ds Max allows arbitrary code execution when processing malicious GIF files. Attackers can exp...

Feb 4, 2026
CVE-2026-0537
7.8

A memory corruption vulnerability in Autodesk 3ds Max allows arbitrary code execution when processing malicious RGB files. This affects all users who ...

Feb 4, 2026
CVE-2026-0538
7.8

A malicious GIF file can trigger an out-of-bounds write vulnerability in Autodesk 3ds Max, allowing attackers to execute arbitrary code with the privi...

Feb 4, 2026
CVE-2026-0659
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious USD files in Autodesk Arnold or 3ds Max. Affect...

Feb 4, 2026
CVE-2026-0661
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious RGB files in Autodesk 3ds Max. Users who open u...

Feb 4, 2026
CVE-2026-20412
7.8

CVE-2026-20412 is an out-of-bounds write vulnerability in the cameraisp component that allows local privilege escalation. Attackers with initial Syste...

Feb 2, 2026
CVE-2026-20409
7.8

CVE-2026-20409 is an out-of-bounds write vulnerability in the imgsys component that allows local privilege escalation. Attackers with initial System p...

Feb 2, 2026
CVE-2026-1284
7.8

An out-of-bounds write vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. This aff...

Jan 26, 2026
CVE-2025-71155
7.8

This CVE addresses a memory corruption vulnerability in the KVM (Kernel-based Virtual Machine) subsystem for s390 architecture in the Linux kernel. Mi...

Jan 23, 2026
CVE-2025-12053
7.8

This vulnerability allows local attackers to trigger a buffer overflow in certain drivers by manipulating registry values. It affects systems using sp...

Jan 14, 2026
CVE-2025-12051
7.8

This vulnerability allows local attackers to cause a buffer overflow in certain drivers by manipulating registry values. It affects systems using Insy...

Jan 14, 2026
CVE-2025-12052
7.8

This vulnerability allows local attackers to cause a buffer overflow by manipulating registry values that drivers read using the RTL_QUERY_REGISTRY_DI...

Jan 14, 2026
CVE-2025-12050
7.8

This vulnerability allows local attackers to trigger a buffer overflow in certain driver components by manipulating registry values. It affects system...

Jan 14, 2026

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,947 CVEs classified as CWE-787, with 730 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free