CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,066
Total CVEs
744
Critical
2,109
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 374
2 Adobe 243
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 172
7 Fedoraproject 119
8 Samsung 77
9 Siemens 75
10 Mozilla 67

All Out-of-bounds Write CVEs (3,066)

CVE-2024-52319
7.8

A memory corruption vulnerability in the Linux kernel's hugetlb (huge pages) subsystem where clear_gigantic_page() receives an unaligned address, pote...

Jan 11, 2025
CVE-2024-56784
7.8

This CVE describes an out-of-bounds write vulnerability in the AMD display driver component of the Linux kernel. An attacker with local access could e...

Jan 8, 2025
CVE-2024-55412
7.8

A vulnerability in SUNIX Serial Driver x64 (snxpsamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through craf...

Jan 7, 2025
CVE-2024-55413
7.8

A vulnerability in SUNIX Parallel Driver x64 (snxppamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through sp...

Jan 7, 2025
CVE-2024-53833
7.8

This vulnerability allows local attackers to write beyond allocated memory boundaries in the Android kernel's lwis_transaction.c component, potentiall...

Jan 3, 2025
CVE-2024-53837
7.8

This CVE describes an integer overflow vulnerability in the Android kernel's lwis_periodic_io.c file that allows local privilege escalation without us...

Jan 3, 2025
CVE-2024-53838
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the Exynos video parsing component....

Jan 3, 2025
CVE-2024-43077
7.8

CVE-2024-43077 is a memory corruption vulnerability in Android's devicemem_server.c that allows local attackers to perform out-of-bounds writes, poten...

Jan 3, 2025
CVE-2024-43097
7.8

This vulnerability is an integer overflow in Skia's SkRegion.cpp that leads to out-of-bounds write. It allows local privilege escalation without user ...

Jan 3, 2025
CVE-2024-43768
7.8

CVE-2024-43768 is an integer overflow vulnerability in Skia's SkDeflate.cpp that allows out-of-bounds writes, potentially leading to local privilege e...

Jan 3, 2025
CVE-2024-12835
7.8

This vulnerability allows remote attackers to execute arbitrary code on Delta Electronics DRASimuCAD installations by tricking users into opening mali...

Dec 30, 2024
CVE-2024-56740
7.8

A memory corruption vulnerability in the Linux kernel's NFSv3 LOCALIO implementation allows uninitialized data to propagate through the read handling ...

Dec 29, 2024
CVE-2024-56695
7.8

A stack overflow vulnerability in the Linux kernel's AMD GPU driver could allow local attackers to crash the kernel or potentially execute arbitrary c...

Dec 28, 2024
CVE-2024-56626
7.8

This CVE describes an out-of-bounds write vulnerability in the Linux kernel's ksmbd SMB server component. When 'vfs objects = streams_xattr' is config...

Dec 27, 2024
CVE-2024-56614
7.8

This CVE-2024-56614 is an out-of-bounds write vulnerability in the Linux kernel's XDP socket (xsk) map deletion function. It allows local attackers wi...

Dec 27, 2024
CVE-2024-56548
7.8

This CVE-2024-56548 is a use-after-free vulnerability in the Linux kernel's HFS+ filesystem driver that occurs when the logical block size of a device...

Dec 27, 2024
CVE-2024-53197
7.8

This vulnerability in the Linux kernel's ALSA USB audio subsystem allows a malicious USB device to trigger out-of-bounds memory accesses. Attackers co...

Dec 27, 2024
CVE-2024-53193
7.8

A memory corruption vulnerability in the Linux kernel's Loongson2 clock driver allows writing beyond allocated heap memory boundaries. This can lead t...

Dec 27, 2024
CVE-2022-44512
7.8

CVE-2022-44512 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malici...

Dec 19, 2024
CVE-2024-12671
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious DWFX files in Autodesk Naviswo...

Dec 17, 2024
CVE-2024-12191
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...

Dec 17, 2024
CVE-2024-12193
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...

Dec 17, 2024
CVE-2024-12197
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...

Dec 17, 2024
CVE-2024-12199
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...

Dec 17, 2024
CVE-2024-12178
7.8

This vulnerability allows remote code execution through memory corruption when Autodesk Navisworks processes a malicious DWFX file. Attackers can expl...

Dec 17, 2024
CVE-2024-53003
7.8

CVE-2024-53003 is an out-of-bounds write vulnerability in Substance3D Modeler that could allow arbitrary code execution when a user opens a malicious ...

Dec 10, 2024
CVE-2024-53001
7.8

CVE-2024-53001 is an out-of-bounds write vulnerability in Substance3D Modeler that could allow arbitrary code execution when a user opens a malicious ...

Dec 10, 2024
CVE-2024-52988
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user o...

Dec 10, 2024
CVE-2024-49513
7.8

CVE-2024-49513 is an out-of-bounds write vulnerability in Adobe PDFL SDK that could allow arbitrary code execution when a user opens a malicious PDF f...

Dec 10, 2024
CVE-2024-49538
7.8

Adobe Illustrator versions 29.0.0, 28.7.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary cod...

Dec 10, 2024
CVE-2024-49551
7.8

Adobe Media Encoder versions 25.0, 24.6.3 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...

Dec 10, 2024
CVE-2024-49553
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Media Encoder that could allow arbitrary code execution when a user opens a malicious...

Dec 10, 2024
CVE-2024-54091
7.8

This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting an out-of-bounds write buffer overflow when parsing maliciou...

Dec 10, 2024
CVE-2024-53142
7.8

A buffer overrun vulnerability in the Linux kernel's initramfs cpio archive filename handling allows specially crafted archives to create files with t...

Dec 6, 2024
CVE-2018-9402
7.8

CVE-2018-9402 is a buffer overflow vulnerability in Android's graphics library that allows local attackers to execute arbitrary code with kernel privi...

Dec 5, 2024
CVE-2018-9414
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds stack write in the Bluetooth GATT server component. A...

Dec 2, 2024
CVE-2024-53106
7.8

A buffer overflow vulnerability in the Linux kernel's IMA (Integrity Measurement Architecture) subsystem allows local attackers to potentially execute...

Dec 2, 2024
CVE-2024-53104
7.8

This CVE is an out-of-bounds write vulnerability in the Linux kernel's UVC video driver (uvcvideo). Attackers could exploit this to crash the system o...

Dec 2, 2024
CVE-2024-11803
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Tellus Lite V-Simulator 5 installations by tricking users into o...

Nov 28, 2024
CVE-2024-11797
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...

Nov 28, 2024
CVE-2024-11801
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Tellus Lite V-Simulator 5 installations by tricking users into o...

Nov 28, 2024
CVE-2024-11793
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...

Nov 28, 2024
CVE-2024-53098
7.8

This vulnerability in the Linux kernel's Xe graphics driver allows attackers with local access to pass invalid memory addresses to the ufence subsyste...

Nov 25, 2024
CVE-2024-9260
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit it by ...

Nov 22, 2024
CVE-2024-9114
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious GIF files in FastStone Image Viewer. The...

Nov 22, 2024
CVE-2024-9248
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Nov 22, 2024
CVE-2024-9112
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FastStone Image Viewer by tricking user...

Nov 22, 2024
CVE-2024-7352
7.8

CVE-2024-7352 is a remote code execution vulnerability in PDF-XChange Editor's PDF file parsing. Attackers can execute arbitrary code by tricking user...

Nov 22, 2024
CVE-2024-6822
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit this b...

Nov 22, 2024
CVE-2024-6818
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in IrfanView. The flaw exists ...

Nov 22, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,066 CVEs classified as CWE-787, with 744 rated critical and 2,109 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free