CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,956
Total CVEs
731
Critical
2,012
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 363
2 Linux 228
3 Adobe 217
4 Apple 200
5 Tenda 189
6 Debian 166
7 Fedoraproject 117
8 Samsung 77
9 Siemens 74
10 Mozilla 67

All Out-of-bounds Write CVEs (2,956)

CVE-2025-12051
7.8

This vulnerability allows local attackers to cause a buffer overflow in certain drivers by manipulating registry values. It affects systems using Insy...

Jan 14, 2026
CVE-2025-12052
7.8

This vulnerability allows local attackers to cause a buffer overflow by manipulating registry values that drivers read using the RTL_QUERY_REGISTRY_DI...

Jan 14, 2026
CVE-2025-12050
7.8

This vulnerability allows local attackers to trigger a buffer overflow in certain driver components by manipulating registry values. It affects system...

Jan 14, 2026
CVE-2026-21305
7.8

Substance3D Painter versions 11.0.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a...

Jan 13, 2026
CVE-2026-21306
7.8

CVE-2026-21306 is an out-of-bounds write vulnerability in Substance3D Sampler that could allow arbitrary code execution when a user opens a malicious ...

Jan 13, 2026
CVE-2026-21307
7.8

CVE-2026-21307 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Jan 13, 2026
CVE-2025-47346
7.8

This vulnerability involves memory corruption in the trusted application's secure logging command processing, which could allow attackers to execute a...

Jan 7, 2026
CVE-2025-20800
7.8

CVE-2025-20800 is an out-of-bounds write vulnerability in mminfra that allows local privilege escalation. Attackers with initial System privilege can ...

Jan 6, 2026
CVE-2025-20795
7.8

CVE-2025-20795 is an out-of-bounds write vulnerability in KeyInstall that allows local privilege escalation. Attackers with System privilege can explo...

Jan 6, 2026
CVE-2025-20798
7.8

This vulnerability allows local privilege escalation on MediaTek devices through an out-of-bounds write in the battery subsystem. Attackers with initi...

Jan 6, 2026
CVE-2025-20778
7.8

This CVE describes an out-of-bounds write vulnerability in a display component that could allow local privilege escalation. Attackers who already have...

Jan 6, 2026
CVE-2023-54285
7.8

This CVE addresses an integer overflow vulnerability in the Linux kernel's iomap subsystem that could lead to memory corruption or system crashes. It ...

Dec 30, 2025
CVE-2025-14409
7.8

CVE-2025-14409 is an out-of-bounds write vulnerability in Soda PDF Desktop's PDF file parser that allows remote code execution when a user opens a mal...

Dec 23, 2025
CVE-2025-64461
7.8

An out-of-bounds write vulnerability in NI LabVIEW's mgocre_SH_25_3!RevBL() function allows attackers to execute arbitrary code or disclose informatio...

Dec 18, 2025
CVE-2025-47320
7.8

This vulnerability allows memory corruption during MFC channel configuration while playing music, potentially enabling arbitrary code execution. It af...

Dec 18, 2025
CVE-2025-53524
7.8

Fuji Electric Monitouch V-SFT-6 software is vulnerable to an out-of-bounds write when processing specially crafted project files, which could allow at...

Dec 17, 2025
CVE-2025-9456
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious SLDPRT files in affected Autodesk products. The...

Dec 16, 2025
CVE-2025-9452
7.8

A memory corruption vulnerability in Autodesk products allows arbitrary code execution when parsing malicious SLDPRT files. This affects users of spec...

Dec 16, 2025
CVE-2025-10898
7.8

This CVE describes an out-of-bounds write vulnerability in Autodesk products when parsing malicious MODEL files. Attackers can exploit this to crash a...

Dec 16, 2025
CVE-2025-10899
7.8

This CVE describes an out-of-bounds write vulnerability in Autodesk products when parsing malicious MODEL files. Attackers can exploit this to crash a...

Dec 16, 2025
CVE-2025-10900
7.8

This CVE describes an out-of-bounds write vulnerability in Autodesk products when parsing malicious MODEL files. Attackers can exploit this to crash a...

Dec 16, 2025
CVE-2025-10884
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPART files in affected Autodesk products. It...

Dec 16, 2025
CVE-2025-10888
7.8

This CVE describes an out-of-bounds write vulnerability in Autodesk products when parsing malicious MODEL files. Attackers can exploit this to crash a...

Dec 16, 2025
CVE-2025-10882
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious X_T files in affected Autodesk...

Dec 16, 2025
CVE-2025-43402
7.8

This memory corruption vulnerability in macOS allows malicious applications to cause system crashes or corrupt process memory. It affects macOS system...

Dec 12, 2025
CVE-2025-36935
7.8

This vulnerability allows local privilege escalation through memory corruption in Android's Trusty secure environment. Attackers can exploit uninitial...

Dec 11, 2025
CVE-2025-36925
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the WAVES audio processing library....

Dec 11, 2025
CVE-2025-48638
7.8

CVE-2025-48638 is a kernel vulnerability in Android's pKVM (protected Kernel-based Virtual Machine) tracing subsystem that allows local privilege esca...

Dec 8, 2025
CVE-2025-48623
7.8

This vulnerability allows local privilege escalation in Android's pKVM hypervisor due to an out-of-bounds write in the init_pkvm_hyp_vcpu function. At...

Dec 8, 2025
CVE-2025-48624
7.8

This CVE describes an out-of-bounds write vulnerability in the ARM SMMUv3 driver in the Linux kernel. It allows local attackers to escalate privileges...

Dec 8, 2025
CVE-2025-33189
7.8

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to perform out-of-bounds writes, potentially leading to code execution, ...

Nov 25, 2025
CVE-2025-11795
7.8

A malicious JPG file can trigger an out-of-bounds write vulnerability in Autodesk 3ds Max, allowing attackers to execute arbitrary code with the privi...

Nov 12, 2025
CVE-2025-61828
7.8

Adobe Illustrator on iPad versions 3.0.9 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code...

Nov 11, 2025
CVE-2025-61831
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious f...

Nov 11, 2025
CVE-2025-27713
7.8

This vulnerability is an out-of-bounds write in Intel QAT Windows software that allows authenticated local attackers to escalate privileges. It affect...

Nov 11, 2025
CVE-2025-47367
7.8

This CVE describes a memory corruption vulnerability in Qualcomm IOCTL processing that could allow attackers to execute arbitrary code or cause denial...

Nov 4, 2025
CVE-2025-27070
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's encryption/decryption command processing. Attackers could exploit this to execute a...

Nov 4, 2025
CVE-2025-10920
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ICNS files in GIMP. The flaw exists in I...

Oct 29, 2025
CVE-2025-54283
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious f...

Oct 14, 2025
CVE-2025-54280
7.8

Substance3D Viewer versions 0.25.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a ...

Oct 14, 2025
CVE-2025-54273
7.8

CVE-2025-54273 is an out-of-bounds write vulnerability in Substance3D Viewer that allows arbitrary code execution when a user opens a malicious file. ...

Oct 14, 2025
CVE-2025-22831
7.8

CVE-2025-22831 is an out-of-bounds write vulnerability in AMI APTIOV BIOS firmware that allows local attackers to corrupt data and disrupt system avai...

Oct 14, 2025
CVE-2025-40809
7.8

An out-of-bounds write vulnerability in Solid Edge SE2024 and SE2025 allows attackers to crash the application or execute arbitrary code by tricking u...

Oct 14, 2025
CVE-2025-20723
7.8

This CVE describes an out-of-bounds write vulnerability in the GNSS driver that allows local privilege escalation. Attackers with initial System privi...

Oct 14, 2025
CVE-2025-20715
7.8

This CVE describes an out-of-bounds write vulnerability in MediaTek's wlan AP driver due to incorrect bounds checking. It allows local privilege escal...

Oct 14, 2025
CVE-2025-61858
7.8

An out-of-bounds write vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to execute arbitrary code by tricking users into opening malicious...

Oct 10, 2025
CVE-2025-39962
7.8

This CVE-2025-39962 is an integer overflow vulnerability in the Linux kernel's rxrpc subsystem that could allow local attackers to cause denial of ser...

Oct 9, 2025
CVE-2025-47355
7.8

This vulnerability allows memory corruption through improper handling of remote procedure IOCTL calls, potentially leading to arbitrary code execution...

Oct 9, 2025
CVE-2023-53680
7.8

A Linux kernel vulnerability in NFSD (Network File System Daemon) allows out-of-bounds array access when processing malformed NFSv4 compound operation...

Oct 7, 2025
CVE-2023-53652
7.8

This CVE-2023-53652 is an out-of-bounds read vulnerability in the Linux kernel's vDPA (virtual Data Path Acceleration) subsystem. It allows attackers ...

Oct 7, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,956 CVEs classified as CWE-787, with 731 rated critical and 2,012 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free