CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,081
Total CVEs
744
Critical
2,124
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 374
2 Adobe 243
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 172
7 Fedoraproject 119
8 Samsung 77
9 Siemens 75
10 Mozilla 69

All Out-of-bounds Write CVEs (3,081)

CVE-2024-11793
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fuji Electric Monitouch V-SFT installations by tricking users into opening mal...

Nov 28, 2024
CVE-2024-53098
7.8

This vulnerability in the Linux kernel's Xe graphics driver allows attackers with local access to pass invalid memory addresses to the ufence subsyste...

Nov 25, 2024
CVE-2024-9260
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit it by ...

Nov 22, 2024
CVE-2024-9114
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious GIF files in FastStone Image Viewer. The...

Nov 22, 2024
CVE-2024-9248
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Nov 22, 2024
CVE-2024-9112
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FastStone Image Viewer by tricking user...

Nov 22, 2024
CVE-2024-7352
7.8

CVE-2024-7352 is a remote code execution vulnerability in PDF-XChange Editor's PDF file parsing. Attackers can execute arbitrary code by tricking user...

Nov 22, 2024
CVE-2024-6822
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView. Attackers can exploit this b...

Nov 22, 2024
CVE-2024-6818
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-6820
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious AWD files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-9747
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSD files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-9735
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-9737
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-9733
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-8827
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Nov 22, 2024
CVE-2024-8830
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XPS files in PDF-XChange Editor. The fla...

Nov 22, 2024
CVE-2024-8813
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

Nov 22, 2024
CVE-2024-8817
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U...

Nov 22, 2024
CVE-2024-11579
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious OBJ files in Luxion KeyShot. The flaw ex...

Nov 22, 2024
CVE-2024-11577
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious SKP file...

Nov 22, 2024
CVE-2024-11555
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11559
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11549
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11533
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DXF files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-11517
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPM files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-11515
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPM files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-5875
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SHP files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-5877
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PIC files in IrfanView. The flaw exists ...

Nov 22, 2024
CVE-2024-5513
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Kofax Power PDF. The ...

Nov 22, 2024
CVE-2018-9424
7.8

CVE-2018-9424 is an out-of-bounds write vulnerability in Android's CryptoPlugin that allows local privilege escalation without user interaction. Attac...

Nov 19, 2024
CVE-2018-9367
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the camera tuning parameters component. Atta...

Nov 19, 2024
CVE-2018-9372
7.8

CVE-2018-9372 is an out-of-bounds write vulnerability in Android's bootloader that allows local privilege escalation without user interaction. Attacke...

Nov 19, 2024
CVE-2018-9341
7.8

CVE-2018-9341 is an out-of-bounds write vulnerability in Android's MPEG-2 video decoder that could allow remote arbitrary code execution. Attackers co...

Nov 19, 2024
CVE-2024-52573
7.8

This CVE describes an out-of-bounds write vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation products when parsing spec...

Nov 18, 2024
CVE-2024-52571
7.8

This CVE describes an out-of-bounds write vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation products when parsing mali...

Nov 18, 2024
CVE-2024-52569
7.8

This CVE describes an out-of-bounds write vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation products when parsing mali...

Nov 18, 2024
CVE-2024-52565
7.8

This CVE describes an out-of-bounds write vulnerability in Siemens Teamcenter Visualization and Tecnomatix Plant Simulation products when parsing mali...

Nov 18, 2024
CVE-2024-10397
7.8

CVE-2024-10397 is a memory corruption vulnerability in OpenAFS client utilities where a malicious AFS server can crash the cache manager or potentiall...

Nov 14, 2024
CVE-2024-23715
7.8

CVE-2024-23715 is a kernel vulnerability in Android's PMR component that allows local privilege escalation through an out-of-bounds write. Attackers c...

Nov 13, 2024
CVE-2024-49519
7.8

CVE-2024-49519 is an out-of-bounds write vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a malicious ...

Nov 12, 2024
CVE-2024-47433
7.8

CVE-2024-47433 is an out-of-bounds write vulnerability in Adobe Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Nov 12, 2024
CVE-2024-47427
7.8

CVE-2024-47427 is an out-of-bounds write vulnerability in Adobe Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Nov 12, 2024
CVE-2024-47429
7.8

CVE-2024-47429 is an out-of-bounds write vulnerability in Adobe Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Nov 12, 2024
CVE-2024-47452
7.8

Adobe Illustrator versions 28.7.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a...

Nov 12, 2024
CVE-2024-47441
7.8

CVE-2024-47441 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Nov 12, 2024
CVE-2024-47443
7.8

CVE-2024-47443 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Nov 12, 2024
CVE-2024-49528
7.8

Adobe Animate versions 23.0.7, 24.0.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on...

Nov 12, 2024
CVE-2024-50230
7.8

A Linux kernel vulnerability in the nilfs2 filesystem where a missing flag clearing causes directory operations to skip sanity checks after filesystem...

Nov 9, 2024
CVE-2024-50221
7.8

This CVE describes a kernel memory out-of-bounds write vulnerability in the AMD GPU driver for Linux systems with Vangogh architecture GPUs. The vulne...

Nov 9, 2024
CVE-2024-50180
7.8

This CVE describes a buffer overflow vulnerability in the sisfb framebuffer driver in the Linux kernel. An attacker could exploit this to cause a kern...

Nov 8, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,081 CVEs classified as CWE-787, with 744 rated critical and 2,124 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free