CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,004
Total CVEs
736
Critical
2,055
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 369
2 Adobe 243
3 Linux 229
4 Apple 200
5 Tenda 189
6 Debian 170
7 Fedoraproject 117
8 Samsung 77
9 Siemens 75
10 Mozilla 67

All Out-of-bounds Write CVEs (3,004)

CVE-2025-38226
7.8

A memory corruption vulnerability in the Linux kernel's VIVID test driver allows out-of-bounds writes when processing video composition data. This aff...

Jul 4, 2025
CVE-2025-38179
7.8

A buffer overflow vulnerability in the Linux kernel's SMB client allows attackers to write beyond allocated memory boundaries when processing RDMA ope...

Jul 4, 2025
CVE-2025-38157
7.8

A vulnerability in the Linux kernel's ath9k_htc WiFi driver allows a malicious USB device to trigger a divide-by-zero error by sending a WMI_SWBA_EVEN...

Jul 3, 2025
CVE-2025-38133
7.8

A memory corruption vulnerability in the Linux kernel's AD4851/AD4858 IIO ADC driver allows attackers to cause undefined behavior or system crashes. T...

Jul 3, 2025
CVE-2025-38101
7.8

A race condition vulnerability in the Linux kernel's ring buffer subsystem could allow local attackers to corrupt kernel memory or cause denial of ser...

Jul 3, 2025
CVE-2025-6654
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025
CVE-2025-6659
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files in PDF-XChange Editor. The fla...

Jun 25, 2025
CVE-2025-6647
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025
CVE-2025-6651
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Jun 25, 2025
CVE-2022-50185
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's Radeon graphics driver. An attacker with local access could exploit this...

Jun 18, 2025
CVE-2022-50156
7.8

A buffer overflow vulnerability in the Linux kernel's cp2112 HID driver allows local attackers to write beyond allocated memory boundaries. This affec...

Jun 18, 2025
CVE-2022-50142
7.8

This vulnerability in the Linux kernel's Intel TH (Trace Hub) MSU (Memory Storage Unit) driver allows improper handling of vmalloc-allocated DMA buffe...

Jun 18, 2025
CVE-2022-50131
7.8

This is a buffer overflow vulnerability in the Linux kernel's HID mcp2221 driver. It allows attackers to write beyond allocated memory boundaries in t...

Jun 18, 2025
CVE-2022-50050
7.8

This CVE describes a potential buffer overflow vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem for Intel HDA audio drivers. Th...

Jun 18, 2025
CVE-2022-50052
7.8

This CVE describes a potential buffer overflow vulnerability in the Linux kernel's ASoC Intel AVS driver. The vulnerability could allow local attacker...

Jun 18, 2025
CVE-2022-50040
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's sja1105 DSA driver. When an error occurs during devlink region creation, the ...

Jun 18, 2025
CVE-2022-50030
7.8

A buffer overflow vulnerability in the Linux kernel's lpfc SCSI driver debugfs interface allows attackers to crash systems or potentially execute arbi...

Jun 18, 2025
CVE-2022-49999
7.8

A race condition in the Linux kernel's Btrfs filesystem allows double allocation of disk space, potentially corrupting the free space tree and causing...

Jun 18, 2025
CVE-2022-49950
7.8

A memory corruption vulnerability in the Linux kernel's fastrpc driver allows local attackers to corrupt kernel memory by opening a fastrpc device whe...

Jun 18, 2025
CVE-2022-49952
7.8

A memory corruption vulnerability in the Linux kernel's fastrpc driver allows attackers to write beyond allocated memory boundaries when too many sess...

Jun 18, 2025
CVE-2025-38068
7.8

A buffer overflow vulnerability exists in the Linux kernel's LZO compression implementation. Attackers can exploit this to write beyond allocated memo...

Jun 18, 2025
CVE-2025-41413
7.8

Fuji Electric Smart Editor contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected systems. Thi...

Jun 17, 2025
CVE-2025-43575
7.8

Adobe Acrobat Reader has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious PDF file. This affect...

Jun 10, 2025
CVE-2025-43581
7.8

CVE-2025-43581 is an out-of-bounds write vulnerability in Substance3D Sampler versions 5.0 and earlier that could allow arbitrary code execution when ...

Jun 10, 2025
CVE-2025-47108
7.8

CVE-2025-47108 is an out-of-bounds write vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a malicious ...

Jun 10, 2025
CVE-2025-43593
7.8

Adobe InDesign has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users of...

Jun 10, 2025
CVE-2025-46715
7.8

This vulnerability in Sandboxie allows any user on a Windows system, including low-privileged processes, to write arbitrary registry key contents to k...

May 22, 2025
CVE-2025-37979
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's ASoC (Audio System on Chip) driver for Qualcomm sc7280 LPASS (Low Power Audio...

May 20, 2025
CVE-2025-37981
7.8

A memory corruption vulnerability in the Linux kernel's smartpqi SCSI driver could allow attackers to write driver logs to system memory after kexec r...

May 20, 2025
CVE-2025-37943
7.8

A memory corruption vulnerability in the Linux kernel's ath12k Wi-Fi driver allows attackers to potentially execute arbitrary code or crash the system...

May 20, 2025
CVE-2025-37927
7.8

A buffer overflow vulnerability exists in the Linux kernel's AMD IOMMU driver when parsing ACPI HID/UID strings. This allows local attackers to potent...

May 20, 2025
CVE-2025-37923
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's tracing subsystem. The trace_seq_to_buffer() function can copy more data...

May 20, 2025
CVE-2025-47750
7.8

This vulnerability in V-SFT v6.2.5.0 and earlier allows attackers to execute arbitrary code by exploiting an out-of-bounds write when opening speciall...

May 19, 2025
CVE-2025-47752
7.8

This vulnerability in V-SFT v6.2.5.0 and earlier allows attackers to execute arbitrary code by exploiting an out-of-bounds write when opening speciall...

May 19, 2025
CVE-2025-30417
7.8

A memory corruption vulnerability in NI Circuit Design Suite's SymbolEditor allows attackers to execute arbitrary code or disclose information by tric...

May 15, 2025
CVE-2025-43569
7.8

CVE-2025-43569 is an out-of-bounds write vulnerability in Substance3D Stager that allows arbitrary code execution when a user opens a malicious file. ...

May 13, 2025
CVE-2025-43548
7.8

Adobe Dimension versions 4.1.2 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a ...

May 13, 2025
CVE-2025-30322
7.8

CVE-2025-30322 is an out-of-bounds write vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a malicious ...

May 13, 2025
CVE-2025-30328
7.8

Adobe Animate versions 24.0.8, 23.0.11 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code o...

May 13, 2025
CVE-2025-30318
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file...

May 13, 2025
CVE-2025-1329
7.8

This vulnerability allows a local user to execute arbitrary code on IBM CICS TX systems due to improper handling of DNS return requests by the gethost...

May 8, 2025
CVE-2025-37810
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's DWC3 USB gadget driver. An attacker could trigger a kernel crash...

May 8, 2025
CVE-2025-21468
7.8

This vulnerability allows memory corruption in Qualcomm firmware drivers when processing responses. Attackers could potentially execute arbitrary code...

May 6, 2025
CVE-2024-49835
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's secure file reading functionality. Attackers could exploit this to execute arbitrar...

May 6, 2025
CVE-2025-20668
7.8

This CVE describes an out-of-bounds write vulnerability in scp that could allow local privilege escalation. Attackers who already have System privileg...

May 5, 2025
CVE-2023-53142
7.8

A buffer overflow vulnerability in the Linux kernel's ice network driver allows reading incorrect data from SFP module EEPROMs. This affects systems u...

May 2, 2025
CVE-2023-53081
7.8

A race condition vulnerability in the Linux kernel's OCFS2 filesystem can cause data corruption when buffered writes fail. This occurs when a failed w...

May 2, 2025
CVE-2023-53077
7.8

This CVE-2023-53077 is a shift-out-of-bounds vulnerability in the AMD display driver component of the Linux kernel. When PTEBufferSizeInRequests is ze...

May 2, 2025
CVE-2023-53065
7.8

A stack-based buffer overflow vulnerability in the Linux kernel's perf subsystem allows local attackers to corrupt kernel memory. This affects Linux s...

May 2, 2025
CVE-2025-1883
7.8

An out-of-bounds write vulnerability in SOLIDWORKS eDrawings' OBJ file parser allows arbitrary code execution when opening malicious OBJ files. This a...

May 2, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,004 CVEs classified as CWE-787, with 736 rated critical and 2,055 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free