CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,041
Total CVEs
744
Critical
2,084
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 373
2 Adobe 243
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 172
7 Fedoraproject 119
8 Samsung 77
9 Siemens 75
10 Mozilla 67

All Out-of-bounds Write CVEs (3,041)

CVE-2022-49612
7.8

This CVE-2022-49612 is a Linux kernel vulnerability in power supply subsystem interpolation functions that causes out-of-bounds memory reads. It affec...

Feb 26, 2025
CVE-2022-49592
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's STMicroelectronics STMMAC Ethernet driver. When queue numbers exceed 4, a 3...

Feb 26, 2025
CVE-2022-49581
7.8

This is a buffer overflow vulnerability in the Linux kernel's be2net driver that allows attackers to write beyond allocated memory boundaries when rea...

Feb 26, 2025
CVE-2022-49292
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's ALSA OSS PCM layer that can cause kernel memory allocation failures. Attack...

Feb 26, 2025
CVE-2022-49073
7.8

This vulnerability is an out-of-bounds write in the Linux kernel's sata_dwc_460ex driver that can cause kernel crashes or potential privilege escalati...

Feb 26, 2025
CVE-2022-49044
7.8

A memory corruption vulnerability in the Linux kernel's dm-integrity subsystem allows attackers to write beyond allocated buffer boundaries when tag_s...

Feb 26, 2025
CVE-2021-47640
7.8

A memory corruption vulnerability in the Linux kernel's KASAN (Kernel Address SANitizer) subsystem on PowerPC architecture causes incorrect shadow pag...

Feb 26, 2025
CVE-2021-47642
7.8

This CVE describes a buffer overflow vulnerability in the NVIDIA framebuffer driver (nvidiafb) in the Linux kernel. The vulnerability allows an attack...

Feb 26, 2025
CVE-2025-26596
7.8

A heap buffer overflow vulnerability in X.Org and Xwayland allows attackers to write beyond allocated memory boundaries. This affects systems using X1...

Feb 25, 2025
CVE-2025-26598
7.8

This CVE describes an out-of-bounds write vulnerability in X.Org and Xwayland where the GetBarrierDevice() function incorrectly returns the last eleme...

Feb 25, 2025
CVE-2025-21704
7.8

A memory corruption vulnerability in the Linux kernel's USB CDC-ACM driver allows attackers to corrupt kernel memory when processing fragmented USB co...

Feb 22, 2025
CVE-2025-1471
7.8

This CVE describes a buffer overflow vulnerability in Eclipse OMR's z/OS atoe print functions. Attackers could exploit this to execute arbitrary code ...

Feb 21, 2025
CVE-2024-31858
7.8

This vulnerability in Intel QuickAssist Technology software allows an authenticated attacker with local access to perform an out-of-bounds write, pote...

Feb 12, 2025
CVE-2025-21161
7.8

CVE-2025-21161 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Feb 11, 2025
CVE-2025-21157
7.8

Adobe InDesign has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users of...

Feb 11, 2025
CVE-2023-39943
7.8

This vulnerability in Ashlar-Vellum Cobalt allows attackers to execute arbitrary code by exploiting improper validation when parsing XE files. It affe...

Feb 4, 2025
CVE-2025-20631
7.8

This vulnerability in MediaTek wlan AP driver allows local attackers to write beyond allocated memory boundaries due to improper bounds checking. Succ...

Feb 3, 2025
CVE-2025-20632
7.8

This vulnerability in MediaTek wlan AP driver allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated privile...

Feb 3, 2025
CVE-2024-54517
7.8

This vulnerability allows a malicious app to corrupt coprocessor memory on Apple devices, potentially leading to system instability or unauthorized co...

Jan 27, 2025
CVE-2024-54522
7.8

This vulnerability allows malicious applications to corrupt coprocessor memory on Apple devices due to insufficient bounds checking. It affects macOS,...

Jan 27, 2025
CVE-2024-54509
7.8

This CVE describes an out-of-bounds write vulnerability in macOS kernel memory that could allow a malicious application to cause system crashes or wri...

Jan 27, 2025
CVE-2024-50664
7.8

This vulnerability is a heap buffer overflow in gpac's MP4Box tool that occurs when processing specially crafted MP4 files. Attackers could exploit th...

Jan 23, 2025
CVE-2024-49738
7.8

This vulnerability allows an attacker to write data outside the intended memory buffer in Android's Parcel component, potentially leading to local pri...

Jan 21, 2025
CVE-2024-49745
7.8

This CVE describes an out-of-bounds write vulnerability in Android's Parcel component that allows local privilege escalation without user interaction....

Jan 21, 2025
CVE-2025-21650
7.8

This vulnerability in the Linux kernel's HNS3 network driver allows out-of-bounds memory access when reading TQP BAR space information. It affects sys...

Jan 19, 2025
CVE-2018-9389
7.8

This is a heap buffer overflow vulnerability in Android's IPv6 networking stack that allows local privilege escalation without user interaction. Attac...

Jan 18, 2025
CVE-2025-21136
7.8

CVE-2025-21136 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Jan 14, 2025
CVE-2025-21138
7.8

CVE-2025-21138 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Jan 14, 2025
CVE-2025-21132
7.8

CVE-2025-21132 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...

Jan 14, 2025
CVE-2025-21130
7.8

CVE-2025-21130 is an out-of-bounds write vulnerability in Adobe Substance3D Stager that allows arbitrary code execution when a user opens a malicious ...

Jan 14, 2025
CVE-2025-21131
7.8

CVE-2025-21131 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...

Jan 14, 2025
CVE-2024-57850
7.8

A memory corruption vulnerability exists in the Linux kernel's JFFS2 filesystem rtime decompression routine. This allows attackers with access to corr...

Jan 11, 2025
CVE-2024-51729
7.8

A memory corruption vulnerability in the Linux kernel's hugetlb_wp() function occurs when copy_user_gigantic_page() receives an unaligned address, pot...

Jan 11, 2025
CVE-2024-52319
7.8

A memory corruption vulnerability in the Linux kernel's hugetlb (huge pages) subsystem where clear_gigantic_page() receives an unaligned address, pote...

Jan 11, 2025
CVE-2024-56784
7.8

This CVE describes an out-of-bounds write vulnerability in the AMD display driver component of the Linux kernel. An attacker with local access could e...

Jan 8, 2025
CVE-2024-55412
7.8

A vulnerability in SUNIX Serial Driver x64 (snxpsamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through craf...

Jan 7, 2025
CVE-2024-55413
7.8

A vulnerability in SUNIX Parallel Driver x64 (snxppamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through sp...

Jan 7, 2025
CVE-2024-53833
7.8

This vulnerability allows local attackers to write beyond allocated memory boundaries in the Android kernel's lwis_transaction.c component, potentiall...

Jan 3, 2025
CVE-2024-53837
7.8

This CVE describes an integer overflow vulnerability in the Android kernel's lwis_periodic_io.c file that allows local privilege escalation without us...

Jan 3, 2025
CVE-2024-53838
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the Exynos video parsing component....

Jan 3, 2025
CVE-2024-43077
7.8

CVE-2024-43077 is a memory corruption vulnerability in Android's devicemem_server.c that allows local attackers to perform out-of-bounds writes, poten...

Jan 3, 2025
CVE-2024-43097
7.8

This vulnerability is an integer overflow in Skia's SkRegion.cpp that leads to out-of-bounds write. It allows local privilege escalation without user ...

Jan 3, 2025
CVE-2024-43768
7.8

CVE-2024-43768 is an integer overflow vulnerability in Skia's SkDeflate.cpp that allows out-of-bounds writes, potentially leading to local privilege e...

Jan 3, 2025
CVE-2024-12835
7.8

This vulnerability allows remote attackers to execute arbitrary code on Delta Electronics DRASimuCAD installations by tricking users into opening mali...

Dec 30, 2024
CVE-2024-56740
7.8

A memory corruption vulnerability in the Linux kernel's NFSv3 LOCALIO implementation allows uninitialized data to propagate through the read handling ...

Dec 29, 2024
CVE-2024-56695
7.8

A stack overflow vulnerability in the Linux kernel's AMD GPU driver could allow local attackers to crash the kernel or potentially execute arbitrary c...

Dec 28, 2024
CVE-2024-56626
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's ksmbd SMB server component. When 'vfs objects = streams_xattr' is config...

Dec 27, 2024
CVE-2024-56614
7.8

This CVE-2024-56614 is an out-of-bounds write vulnerability in the Linux kernel's XDP socket (xsk) map deletion function. It allows local attackers wi...

Dec 27, 2024
CVE-2024-56548
7.8

This CVE-2024-56548 is a use-after-free vulnerability in the Linux kernel's HFS+ filesystem driver that occurs when the logical block size of a device...

Dec 27, 2024
CVE-2024-53197
7.8

This vulnerability in the Linux kernel's ALSA USB audio subsystem allows a malicious USB device to trigger out-of-bounds memory accesses. Attackers co...

Dec 27, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,041 CVEs classified as CWE-787, with 744 rated critical and 2,084 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free