CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,947)
This vulnerability in Vyper smart contract language allows memory corruption when using specific builtin functions with complex expressions, potential...
Sep 18, 2023An out-of-bounds write vulnerability in Bitdefender Engines on Windows allows memory corruption that can crash the engine. This affects Bitdefender pr...
Jul 14, 2023This vulnerability allows attackers with network access to VMware vCenter Server to send specially crafted DCERPC packets causing memory corruption th...
Jun 22, 2023This CVE describes a heap overflow vulnerability in vCenter Server's DCERPC protocol implementation due to uninitialized memory usage. Attackers with ...
Jun 22, 2023This CVE allows remote attackers to execute arbitrary code on affected ArubaOS-Switch devices, potentially leading to complete system compromise. It a...
May 10, 2022This vulnerability allows remote attackers to execute arbitrary code on affected Mikrotik RouterOS devices by exploiting a heap-based buffer overflow ...
Mar 16, 2022A stack buffer overflow vulnerability in QNAP NAS Multimedia Console allows attackers to execute arbitrary code on affected systems. This affects QNAP...
Nov 13, 2021This memory corruption vulnerability in macOS allows attackers in a privileged network position to execute arbitrary code on affected systems. It affe...
Sep 8, 2021This is a stack-based buffer overflow vulnerability in FreeBSD's ggatec daemon that allows remote code execution. Attackers in a privileged network po...
Aug 30, 2021CVE-2021-26221 is an out-of-bounds write vulnerability in ezXML's ezxml_new function that occurs when processing XML files after memory pool exhaustio...
Feb 8, 2021This vulnerability in TensorFlow Lite allows attackers with access to segment_ids_data to trigger out-of-bounds writes to heap-allocated buffers by in...
Sep 25, 2020This vulnerability in TensorFlow Lite allows memory corruption when processing models with unsorted segment IDs in segment sum operations. It affects ...
Sep 25, 2020CVE-2020-1912 is an out-of-bounds read/write vulnerability in Facebook's Hermes JavaScript engine that could allow attackers to execute arbitrary code...
Sep 9, 2020This vulnerability allows a local attacker to write data beyond allocated memory boundaries in Samsung's libaudiosaplus_sec.so library, potentially le...
Sep 3, 2025This vulnerability allows an authenticated attacker on the same local network as affected EZVIZ security cameras to execute arbitrary code via stack b...
Aug 1, 2023This CVE describes an out-of-bounds write vulnerability in Huawei FLMG-10 sound box products. Attackers can exploit this buffer overflow vulnerability...
Jun 16, 2023A stack buffer overflow vulnerability in Realtek RTL8710 and other Ameba-based WiFi chips allows remote code execution. Attackers within Wi-Fi range c...
Jun 4, 2021CVE-2021-3182 is a buffer overflow vulnerability in D-Link DCS-5220 security cameras that allows remote attackers to execute arbitrary code or cause d...
Jan 19, 2021A stack-based buffer overflow vulnerability exists in Realtek Wi-Fi chipset firmware for specific IoT devices. Attackers can exploit this by sending a...
Jul 6, 2020CVE-2021-26383 is a memory corruption vulnerability in AMD's Trusted Execution Environment (TEE) where insufficient bounds checking allows attackers w...
Sep 6, 2025This CVE describes an out-of-bounds write vulnerability in VMware ESXi that could allow a malicious actor with VMX process privileges to escape the sa...
Mar 5, 2024This CVE describes an out-of-bounds write vulnerability in MediaTek's 'da' component due to improper input validation. It allows local privilege escal...
Mar 4, 2024An out-of-bounds write vulnerability in Intel Server Board BMC firmware allows privileged users with local access to escalate privileges. This affects...
May 10, 2023This vulnerability in NVIDIA's Trusty trusted Linux kernel (TLK) allows heap overflows due to insufficient heap hardening. Attackers could exploit thi...
Jun 30, 2021Delta Electronics CNCSoft-G2 has a file parsing vulnerability that allows out-of-bounds write when processing malicious files. This enables remote cod...
Mar 4, 2026This CVE describes a memory corruption vulnerability in Qualcomm Trusted Application (TA) invocation where accessing buffers with invalid length can l...
Mar 2, 2026This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPART files in affected Autodesk products. Us...
Feb 18, 2026An Out-Of-Bounds Write vulnerability in SOLIDWORKS eDrawings allows an attacker to execute arbitrary code by tricking a user into opening a malicious ...
Feb 16, 2026Lightroom Desktop versions 15.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when use...
Feb 10, 2026CVE-2026-21352 is an out-of-bounds write vulnerability in Adobe DNG SDK versions 1.7.1 2410 and earlier that could allow arbitrary code execution when...
Feb 10, 2026CVE-2026-21346 is an out-of-bounds write vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious file. T...
Feb 10, 2026CVE-2026-21341 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...
Feb 10, 2026Substance3D Designer versions 15.1.0 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a...
Feb 10, 2026Adobe After Effects versions 25.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a v...
Feb 10, 2026CVE-2026-21318 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...
Feb 10, 2026Adobe Audition versions 25.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a user...
Feb 10, 2026An out-of-bounds write vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into openin...
Feb 10, 2026A stack-based buffer overflow vulnerability in Autodesk 3ds Max allows arbitrary code execution when processing malicious GIF files. Attackers can exp...
Feb 4, 2026A memory corruption vulnerability in Autodesk 3ds Max allows arbitrary code execution when processing malicious RGB files. This affects all users who ...
Feb 4, 2026A malicious GIF file can trigger an out-of-bounds write vulnerability in Autodesk 3ds Max, allowing attackers to execute arbitrary code with the privi...
Feb 4, 2026This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious USD files in Autodesk Arnold or 3ds Max. Affect...
Feb 4, 2026This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious RGB files in Autodesk 3ds Max. Users who open u...
Feb 4, 2026CVE-2026-20412 is an out-of-bounds write vulnerability in the cameraisp component that allows local privilege escalation. Attackers with initial Syste...
Feb 2, 2026CVE-2026-20409 is an out-of-bounds write vulnerability in the imgsys component that allows local privilege escalation. Attackers with initial System p...
Feb 2, 2026An out-of-bounds write vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. This aff...
Jan 26, 2026This CVE addresses a memory corruption vulnerability in the KVM (Kernel-based Virtual Machine) subsystem for s390 architecture in the Linux kernel. Mi...
Jan 23, 2026This vulnerability allows local attackers to trigger a buffer overflow in certain drivers by manipulating registry values. It affects systems using sp...
Jan 14, 2026This vulnerability allows local attackers to cause a buffer overflow in certain drivers by manipulating registry values. It affects systems using Insy...
Jan 14, 2026This vulnerability allows local attackers to cause a buffer overflow by manipulating registry values that drivers read using the RTL_QUERY_REGISTRY_DI...
Jan 14, 2026This vulnerability allows local attackers to trigger a buffer overflow in certain driver components by manipulating registry values. It affects system...
Jan 14, 2026About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,947 CVEs classified as CWE-787, with 730 rated critical and 2,004 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free