CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,029
Total CVEs
739
Critical
2,077
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 372
2 Adobe 243
3 Linux 229
4 Apple 200
5 Tenda 189
6 Debian 171
7 Fedoraproject 117
8 Samsung 77
9 Siemens 75
10 Mozilla 67

All Out-of-bounds Write CVEs (3,029)

CVE-2025-20668
7.8

This CVE describes an out-of-bounds write vulnerability in scp that could allow local privilege escalation. Attackers who already have System privileg...

May 5, 2025
CVE-2023-53142
7.8

A buffer overflow vulnerability in the Linux kernel's ice network driver allows reading incorrect data from SFP module EEPROMs. This affects systems u...

May 2, 2025
CVE-2023-53081
7.8

A race condition vulnerability in the Linux kernel's OCFS2 filesystem can cause data corruption when buffered writes fail. This occurs when a failed w...

May 2, 2025
CVE-2023-53077
7.8

This CVE-2023-53077 is a shift-out-of-bounds vulnerability in the AMD display driver component of the Linux kernel. When PTEBufferSizeInRequests is ze...

May 2, 2025
CVE-2023-53065
7.8

A stack-based buffer overflow vulnerability in the Linux kernel's perf subsystem allows local attackers to corrupt kernel memory. This affects Linux s...

May 2, 2025
CVE-2025-1883
7.8

An out-of-bounds write vulnerability in SOLIDWORKS eDrawings' OBJ file parser allows arbitrary code execution when opening malicious OBJ files. This a...

May 2, 2025
CVE-2022-49888
7.8

This CVE describes a kernel stack overflow vulnerability in the Linux kernel on ARM64 systems with Cortex-A76 CPUs. When the cortex_a76_erratum_146322...

May 1, 2025
CVE-2022-49804
7.8

A compiler bug in older GCC versions (before 8.4) causes the Linux kernel on s390 architecture to generate corrupted stack pointer code, leading to st...

May 1, 2025
CVE-2025-23158
7.8

A Linux kernel vulnerability in the Venus media driver allows out-of-bounds write due to improper validation of queue size values from firmware. This ...

May 1, 2025
CVE-2025-4124
7.8

Delta Electronics ISPSoft version 3.20 contains an out-of-bounds write vulnerability when parsing ISP files. This allows attackers to execute arbitrar...

Apr 30, 2025
CVE-2025-22882
7.8

Delta Electronics ISPSoft version 3.20 contains a stack-based buffer overflow vulnerability when parsing CBDGL files. This allows attackers to execute...

Apr 30, 2025
CVE-2025-22884
7.8

Delta Electronics ISPSoft version 3.20 contains a stack-based buffer overflow vulnerability when parsing DVP files. This allows attackers to execute a...

Apr 30, 2025
CVE-2025-22056
7.8

A heap out-of-bounds write vulnerability in the Linux kernel's netfilter nft_tunnel module allows attackers to corrupt kernel memory when processing m...

Apr 16, 2025
CVE-2025-22022
7.8

A vulnerability in the Linux kernel's xHCI USB driver allows a malicious USB device to cause memory corruption and potential data leakage. When specif...

Apr 16, 2025
CVE-2025-2631
7.8

An out-of-bounds write vulnerability in NI LabVIEW's InitCPUInformation() function allows attackers to execute arbitrary code or disclose information ...

Apr 9, 2025
CVE-2025-30304
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a use...

Apr 8, 2025
CVE-2025-30297
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code...

Apr 8, 2025
CVE-2025-27182
7.8

CVE-2025-27182 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Apr 8, 2025
CVE-2025-21966
7.8

This vulnerability in the Linux kernel's dm-flakey device mapper target allows memory corruption due to incorrect parameter passing in the optional co...

Apr 1, 2025
CVE-2025-21927
7.8

A memory corruption vulnerability in the Linux kernel's NVMe over TCP implementation allows attackers to cause memory corruption by sending specially ...

Apr 1, 2025
CVE-2025-30464
7.8

This CVE describes an out-of-bounds write vulnerability in macOS kernel memory that could allow a malicious application to cause system crashes or cor...

Mar 31, 2025
CVE-2023-52980
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's ublk driver that can lead to out-of-bounds memory access. When configuring ...

Mar 27, 2025
CVE-2025-21869
7.8

This CVE describes a Linux kernel vulnerability on PowerPC systems where KASAN (Kernel Address Sanitizer) incorrectly reports memory access violations...

Mar 27, 2025
CVE-2025-2480
7.8

Santesoft Sante DICOM Viewer Pro contains an out-of-bounds write vulnerability that allows local attackers to execute arbitrary code by tricking users...

Mar 20, 2025
CVE-2025-2020
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Cobalt softwa...

Mar 11, 2025
CVE-2025-27172
7.8

CVE-2025-27172 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Mar 11, 2025
CVE-2024-58069
7.8

This vulnerability in the Linux kernel's PCF85063 RTC driver allows out-of-bounds memory writes when reading NVMEM data with small buffers. It affects...

Mar 6, 2025
CVE-2024-45782
7.8

This vulnerability in the HFS filesystem driver allows attackers to trigger a heap-based buffer overflow by providing a specially crafted volume name....

Mar 3, 2025
CVE-2025-1125
7.8

This vulnerability in GRUB's HFS filesystem module allows integer overflow when calculating buffer sizes from malicious filesystem metadata. Attackers...

Mar 3, 2025
CVE-2025-21785
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's ARM64 cacheinfo subsystem. The flaw could allow local attackers to corru...

Feb 27, 2025
CVE-2025-21772
7.8

This CVE-2025-21772 is a memory corruption vulnerability in the Linux kernel's Mac partition table handling code. Attackers could exploit this by prov...

Feb 27, 2025
CVE-2025-21734
7.8

A memory corruption vulnerability in the Linux kernel's fastrpc driver allows attackers to pass improperly calculated page sizes when copying non-regi...

Feb 27, 2025
CVE-2025-21735
7.8

A memory corruption vulnerability in the Linux kernel's NFC subsystem allows attackers to cause out-of-bounds writes by sending specially crafted NFC ...

Feb 27, 2025
CVE-2024-58003
7.8

A double-free vulnerability in Linux kernel media drivers for DS90UB913/DS90UB953 chips could cause memory corruption or system crashes when the drive...

Feb 27, 2025
CVE-2024-58004
7.8

This CVE-2024-58004 is a memory corruption vulnerability in the Linux kernel's Intel IPU6 media driver where CPU latency QoS requests are not properly...

Feb 27, 2025
CVE-2024-54456
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's NFS subsystem. The vulnerability occurs in the nfs_sysfs_link_rpc_client() fu...

Feb 27, 2025
CVE-2025-21724
7.8

This CVE-2025-21724 is a shift-out-of-bounds vulnerability in the Linux kernel's iommufd/iova_bitmap component. It could allow local attackers to caus...

Feb 27, 2025
CVE-2024-57983
7.8

A memory corruption vulnerability in the Linux kernel's TH1520 mailbox driver allows writing beyond allocated memory boundaries during suspend/resume ...

Feb 27, 2025
CVE-2022-49722
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's Intel ice network driver when handling Virtual Function (VF) resets. When a...

Feb 26, 2025
CVE-2022-49645
7.8

A double-free vulnerability in the Linux kernel's Panfrost DRM driver allows local attackers to corrupt memory shrinker lists by calling the madvise I...

Feb 26, 2025
CVE-2022-49635
7.8

This CVE is an integer overflow vulnerability in the Linux kernel's i915 graphics driver selftests. It allows local attackers to cause denial of servi...

Feb 26, 2025
CVE-2022-49612
7.8

This CVE-2022-49612 is a Linux kernel vulnerability in power supply subsystem interpolation functions that causes out-of-bounds memory reads. It affec...

Feb 26, 2025
CVE-2022-49592
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's STMicroelectronics STMMAC Ethernet driver. When queue numbers exceed 4, a 3...

Feb 26, 2025
CVE-2022-49581
7.8

This is a buffer overflow vulnerability in the Linux kernel's be2net driver that allows attackers to write beyond allocated memory boundaries when rea...

Feb 26, 2025
CVE-2022-49292
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's ALSA OSS PCM layer that can cause kernel memory allocation failures. Attack...

Feb 26, 2025
CVE-2022-49073
7.8

This vulnerability is an out-of-bounds write in the Linux kernel's sata_dwc_460ex driver that can cause kernel crashes or potential privilege escalati...

Feb 26, 2025
CVE-2022-49044
7.8

A memory corruption vulnerability in the Linux kernel's dm-integrity subsystem allows attackers to write beyond allocated buffer boundaries when tag_s...

Feb 26, 2025
CVE-2021-47640
7.8

A memory corruption vulnerability in the Linux kernel's KASAN (Kernel Address SANitizer) subsystem on PowerPC architecture causes incorrect shadow pag...

Feb 26, 2025
CVE-2021-47642
7.8

This CVE describes a buffer overflow vulnerability in the NVIDIA framebuffer driver (nvidiafb) in the Linux kernel. The vulnerability allows an attack...

Feb 26, 2025
CVE-2025-26596
7.8

A heap buffer overflow vulnerability in X.Org and Xwayland allows attackers to write beyond allocated memory boundaries. This affects systems using X1...

Feb 25, 2025

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,029 CVEs classified as CWE-787, with 739 rated critical and 2,077 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free