CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,066)
A memory corruption vulnerability in the Linux kernel's hugetlb (huge pages) subsystem where clear_gigantic_page() receives an unaligned address, pote...
Jan 11, 2025This CVE describes an out-of-bounds write vulnerability in the AMD display driver component of the Linux kernel. An attacker with local access could e...
Jan 8, 2025A vulnerability in SUNIX Serial Driver x64 (snxpsamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through craf...
Jan 7, 2025A vulnerability in SUNIX Parallel Driver x64 (snxppamd.sys) allows low-privileged users to perform arbitrary I/O port read/write operations through sp...
Jan 7, 2025This vulnerability allows local attackers to write beyond allocated memory boundaries in the Android kernel's lwis_transaction.c component, potentiall...
Jan 3, 2025This CVE describes an integer overflow vulnerability in the Android kernel's lwis_periodic_io.c file that allows local privilege escalation without us...
Jan 3, 2025This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the Exynos video parsing component....
Jan 3, 2025CVE-2024-43077 is a memory corruption vulnerability in Android's devicemem_server.c that allows local attackers to perform out-of-bounds writes, poten...
Jan 3, 2025This vulnerability is an integer overflow in Skia's SkRegion.cpp that leads to out-of-bounds write. It allows local privilege escalation without user ...
Jan 3, 2025CVE-2024-43768 is an integer overflow vulnerability in Skia's SkDeflate.cpp that allows out-of-bounds writes, potentially leading to local privilege e...
Jan 3, 2025This vulnerability allows remote attackers to execute arbitrary code on Delta Electronics DRASimuCAD installations by tricking users into opening mali...
Dec 30, 2024A memory corruption vulnerability in the Linux kernel's NFSv3 LOCALIO implementation allows uninitialized data to propagate through the read handling ...
Dec 29, 2024A stack overflow vulnerability in the Linux kernel's AMD GPU driver could allow local attackers to crash the kernel or potentially execute arbitrary c...
Dec 28, 2024This CVE describes an out-of-bounds write vulnerability in the Linux kernel's ksmbd SMB server component. When 'vfs objects = streams_xattr' is config...
Dec 27, 2024This CVE-2024-56614 is an out-of-bounds write vulnerability in the Linux kernel's XDP socket (xsk) map deletion function. It allows local attackers wi...
Dec 27, 2024This CVE-2024-56548 is a use-after-free vulnerability in the Linux kernel's HFS+ filesystem driver that occurs when the logical block size of a device...
Dec 27, 2024This vulnerability in the Linux kernel's ALSA USB audio subsystem allows a malicious USB device to trigger out-of-bounds memory accesses. Attackers co...
Dec 27, 2024A memory corruption vulnerability in the Linux kernel's Loongson2 clock driver allows writing beyond allocated heap memory boundaries. This can lead t...
Dec 27, 2024CVE-2022-44512 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malici...
Dec 19, 2024This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious DWFX files in Autodesk Naviswo...
Dec 17, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...
Dec 17, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...
Dec 17, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...
Dec 17, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWFX files in Autodesk Navisworks. It affects a...
Dec 17, 2024This vulnerability allows remote code execution through memory corruption when Autodesk Navisworks processes a malicious DWFX file. Attackers can expl...
Dec 17, 2024CVE-2024-53003 is an out-of-bounds write vulnerability in Substance3D Modeler that could allow arbitrary code execution when a user opens a malicious ...
Dec 10, 2024CVE-2024-53001 is an out-of-bounds write vulnerability in Substance3D Modeler that could allow arbitrary code execution when a user opens a malicious ...
Dec 10, 2024Adobe Animate versions 23.0.8, 24.0.5 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user o...
Dec 10, 2024CVE-2024-49513 is an out-of-bounds write vulnerability in Adobe PDFL SDK that could allow arbitrary code execution when a user opens a malicious PDF f...
Dec 10, 2024Adobe Illustrator versions 29.0.0, 28.7.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary cod...
Dec 10, 2024Adobe Media Encoder versions 25.0, 24.6.3 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...
Dec 10, 2024This CVE describes an out-of-bounds write vulnerability in Adobe Media Encoder that could allow arbitrary code execution when a user opens a malicious...
Dec 10, 2024This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting an out-of-bounds write buffer overflow when parsing maliciou...
Dec 10, 2024A buffer overrun vulnerability in the Linux kernel's initramfs cpio archive filename handling allows specially crafted archives to create files with t...
Dec 6, 2024CVE-2018-9402 is a buffer overflow vulnerability in Android's graphics library that allows local attackers to execute arbitrary code with kernel privi...
Dec 5, 2024This vulnerability allows local privilege escalation on Android devices through an out-of-bounds stack write in the Bluetooth GATT server component. A...
Dec 2, 2024A buffer overflow vulnerability in the Linux kernel's IMA (Integrity Measurement Architecture) subsystem allows local attackers to potentially execute...
Dec 2, 2024This CVE is an out-of-bounds write vulnerability in the Linux kernel's UVC video driver (uvcvideo). Attackers could exploit this to crash the system o...
Dec 2, 2024This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Tellus Lite V-Simulator 5 installations by tricking users into o...
Nov 28, 2024This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...
Nov 28, 2024This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Tellus Lite V-Simulator 5 installations by tricking users into o...
Nov 28, 2024This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...
Nov 28, 2024This vulnerability in the Linux kernel's Xe graphics driver allows attackers with local access to pass invalid memory addresses to the ufence subsyste...
Nov 25, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit it by ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious GIF files in FastStone Image Viewer. The...
Nov 22, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FastStone Image Viewer by tricking user...
Nov 22, 2024CVE-2024-7352 is a remote code execution vulnerability in PDF-XChange Editor's PDF file parsing. Attackers can execute arbitrary code by tricking user...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit this b...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in IrfanView. The flaw exists ...
Nov 22, 2024About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,066 CVEs classified as CWE-787, with 744 rated critical and 2,109 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free