CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

2,972
Total CVEs
732
Critical
2,027
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 369
2 Linux 228
3 Adobe 218
4 Apple 200
5 Tenda 189
6 Debian 169
7 Fedoraproject 117
8 Samsung 77
9 Siemens 75
10 Mozilla 67

All Out-of-bounds Write CVEs (2,972)

CVE-2024-49730
7.8

This vulnerability allows local privilege escalation on Android devices through a memory corruption flaw in FuseDaemon.cpp. An attacker could gain ele...

Sep 2, 2025
CVE-2025-38676
7.8

This CVE describes a stack buffer overflow vulnerability in the AMD IOMMU driver of the Linux kernel. An attacker with control over the kernel command...

Aug 26, 2025
CVE-2025-38662
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's MediaTek MT8365 audio subsystem driver. An incorrect size parameter passed ...

Aug 22, 2025
CVE-2025-38568
7.8

A stack-based buffer overflow vulnerability in the Linux kernel's mqprio traffic control module allows writing 4 bytes beyond the allocated buffer whe...

Aug 19, 2025
CVE-2025-38538
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's nbpfaxi DMA engine driver. The flaw allows attackers to corrupt kernel memo...

Aug 16, 2025
CVE-2025-38533
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's libwx network driver where an uninitialized DMA address field could be used...

Aug 16, 2025
CVE-2025-54221
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious file. ...

Aug 12, 2025
CVE-2025-54215
7.8

CVE-2025-54215 is an out-of-bounds write vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious file. T...

Aug 12, 2025
CVE-2025-54210
7.8

Adobe InDesign versions 20.4, 19.5.4 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a...

Aug 12, 2025
CVE-2025-54206
7.8

Adobe InDesign has an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a malicious file. This affects use...

Aug 12, 2025
CVE-2025-54208
7.8

Adobe InDesign versions 20.4, 19.5.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code whe...

Aug 12, 2025
CVE-2025-54187
7.8

Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user ope...

Aug 12, 2025
CVE-2025-49572
7.8

Substance3D Modeler versions 1.22.0 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user ope...

Aug 12, 2025
CVE-2025-49570
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a malicious fil...

Aug 12, 2025
CVE-2025-40762
7.8

An out-of-bounds write vulnerability in Simcenter Femap allows remote code execution when parsing malicious STP files. Attackers can execute arbitrary...

Aug 12, 2025
CVE-2025-6633
7.8

CVE-2025-6633 is an out-of-bounds write vulnerability in Autodesk 3ds Max that allows attackers to execute arbitrary code by tricking users into openi...

Aug 6, 2025
CVE-2025-6637
7.8

CVE-2025-6637 is an out-of-bounds write vulnerability in Autodesk products that allows arbitrary code execution when parsing malicious PRT files. Atta...

Jul 29, 2025
CVE-2025-7675
7.8

CVE-2025-7675 is an out-of-bounds write vulnerability in Autodesk products that parse 3DM files. Attackers can exploit this to crash applications, cor...

Jul 29, 2025
CVE-2025-38484
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's IIO (Industrial I/O) subsystem backend. An attacker could write beyond t...

Jul 28, 2025
CVE-2025-38456
7.8

A memory corruption vulnerability in the Linux kernel's IPMI message handler could allow attackers to crash systems or potentially execute arbitrary c...

Jul 25, 2025
CVE-2025-38428
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's IMS-PCU driver where improper validation of firmware-supplied length values...

Jul 25, 2025
CVE-2025-38401
7.8

A memory corruption vulnerability in the Linux kernel's MediaTek SD card driver (mtk-sd) occurs when DMA mapping fails but the driver proceeds with DM...

Jul 25, 2025
CVE-2025-38394
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's HID appletb-kbd driver. When a probe failure occurs after registering an input...

Jul 25, 2025
CVE-2025-7260
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7238
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files with IrfanView's CADImage plug...

Jul 21, 2025
CVE-2025-7228
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of INVT VT-Designer by tricking users into...

Jul 21, 2025
CVE-2025-7234
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView with the CADImage plugin. Att...

Jul 21, 2025
CVE-2025-7222
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious 3DM file...

Jul 21, 2025
CVE-2025-7224
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of INVT HMITool by tricking users into ope...

Jul 21, 2025
CVE-2025-7226
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of INVT HMITool by tricking users into ope...

Jul 21, 2025
CVE-2025-38348
7.8

A buffer overflow vulnerability in the Linux kernel's p54 wifi driver allows a malicious USB device posing as an Intersil p54 wifi interface to trigge...

Jul 10, 2025
CVE-2025-38317
7.8

A buffer overflow vulnerability exists in the ath12k WiFi driver's debugfs interface in the Linux kernel, allowing root users to write more than 32 by...

Jul 10, 2025
CVE-2025-38267
7.8

This CVE describes a Linux kernel vulnerability in the ring buffer subsystem where a commit_overrun scenario can trigger a WARN_ON_ONCE() warning. Thi...

Jul 10, 2025
CVE-2025-47133
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code...

Jul 8, 2025
CVE-2025-47127
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code...

Jul 8, 2025
CVE-2025-47129
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a use...

Jul 8, 2025
CVE-2025-49526
7.8

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a us...

Jul 8, 2025
CVE-2025-49530
7.8

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a us...

Jul 8, 2025
CVE-2025-43594
7.8

Adobe InDesign versions 19.5.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a vict...

Jul 8, 2025
CVE-2025-21166
7.8

CVE-2025-21166 is an out-of-bounds write vulnerability in Substance3D Designer that allows arbitrary code execution when a user opens a malicious file...

Jul 8, 2025
CVE-2025-21164
7.8

CVE-2025-21164 is an out-of-bounds write vulnerability in Substance3D Designer that allows arbitrary code execution when a user opens a malicious file...

Jul 8, 2025
CVE-2025-38226
7.8

A memory corruption vulnerability in the Linux kernel's VIVID test driver allows out-of-bounds writes when processing video composition data. This aff...

Jul 4, 2025
CVE-2025-38179
7.8

A buffer overflow vulnerability in the Linux kernel's SMB client allows attackers to write beyond allocated memory boundaries when processing RDMA ope...

Jul 4, 2025
CVE-2025-38157
7.8

A vulnerability in the Linux kernel's ath9k_htc WiFi driver allows a malicious USB device to trigger a divide-by-zero error by sending a WMI_SWBA_EVEN...

Jul 3, 2025
CVE-2025-38133
7.8

A memory corruption vulnerability in the Linux kernel's AD4851/AD4858 IIO ADC driver allows attackers to cause undefined behavior or system crashes. T...

Jul 3, 2025
CVE-2025-38101
7.8

A race condition vulnerability in the Linux kernel's ring buffer subsystem could allow local attackers to corrupt kernel memory or cause denial of ser...

Jul 3, 2025
CVE-2025-6654
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025
CVE-2025-6659
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files in PDF-XChange Editor. The fla...

Jun 25, 2025
CVE-2025-6647
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025
CVE-2025-6651
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 2,972 CVEs classified as CWE-787, with 732 rated critical and 2,027 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free