CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,101
Total CVEs
747
Critical
2,141
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 378
2 Adobe 243
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 173
7 Fedoraproject 120
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,101)

CVE-2024-47441
7.8

CVE-2024-47441 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Nov 12, 2024
CVE-2024-47443
7.8

CVE-2024-47443 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Nov 12, 2024
CVE-2024-49528
7.8

Adobe Animate versions 23.0.7, 24.0.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on...

Nov 12, 2024
CVE-2024-50230
7.8

A Linux kernel vulnerability in the nilfs2 filesystem where a missing flag clearing causes directory operations to skip sanity checks after filesystem...

Nov 9, 2024
CVE-2024-50221
7.8

This CVE describes a kernel memory out-of-bounds write vulnerability in the AMD GPU driver for Linux systems with Vangogh architecture GPUs. The vulne...

Nov 9, 2024
CVE-2024-50180
7.8

This CVE describes a buffer overflow vulnerability in the sisfb framebuffer driver in the Linux kernel. An attacker could exploit this to cause a kern...

Nov 8, 2024
CVE-2024-50129
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's PSE-PD (Power Sourcing Equipment - Power Delivery) subsystem. An...

Nov 5, 2024
CVE-2024-49522
7.8

CVE-2024-49522 is an out-of-bounds write vulnerability in Substance3D Painter that allows arbitrary code execution when a user opens a malicious file....

Nov 5, 2024
CVE-2024-8596
7.8

This vulnerability allows attackers to execute arbitrary code on AutoCAD systems by tricking users into opening malicious MODEL files. It affects Auto...

Oct 29, 2024
CVE-2024-7991
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious DWG files in Autodesk AutoCAD. It affects AutoC...

Oct 29, 2024
CVE-2024-44277
7.8

This is a memory corruption vulnerability in Apple's iOS, iPadOS, visionOS, and tvOS kernels that allows malicious apps to cause system crashes or cor...

Oct 28, 2024
CVE-2024-44218
7.8

This vulnerability allows an attacker to cause heap corruption by tricking a user into processing a maliciously crafted file. Successful exploitation ...

Oct 28, 2024
CVE-2024-44126
7.8

This vulnerability allows an attacker to cause heap corruption by tricking a user into processing a maliciously crafted file. Successful exploitation ...

Oct 28, 2024
CVE-2024-50067
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's uprobe subsystem. When fetching user-space arguments for tracing...

Oct 28, 2024
CVE-2024-47035
7.8

This CVE describes a logic error in the virtio_ring.h header file that allows an out-of-bounds write, potentially leading to local privilege escalatio...

Oct 25, 2024
CVE-2024-47012
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the mobile management component. At...

Oct 25, 2024
CVE-2022-48998
7.8

A stack corruption vulnerability in the Linux kernel's BPF JIT compiler for 32-bit PowerPC systems allows attackers to write beyond the stack boundary...

Oct 21, 2024
CVE-2022-48980
7.8

This is an out-of-bounds write vulnerability in the Linux kernel's SJA1105/SJA1110 Ethernet switch driver. It allows attackers with local access to po...

Oct 21, 2024
CVE-2024-47695
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's RDMA/rtrs-clt subsystem. The flaw occurs during connection clean...

Oct 21, 2024
CVE-2024-47697
7.8

This vulnerability in the Linux kernel's RTL2830 DVB frontend driver allows an out-of-bounds write when processing PID filter operations. An attacker ...

Oct 21, 2024
CVE-2024-7993
7.8

This vulnerability allows an attacker to execute arbitrary code by tricking a user into opening a malicious PDF file in Autodesk Revit. It affects all...

Oct 16, 2024
CVE-2024-47963
7.8

Delta Electronics CNCSoft-G2 has a memory corruption vulnerability where improper validation of user-supplied data allows writing past allocated objec...

Oct 10, 2024
CVE-2024-47670
7.8

This CVE describes an out-of-bounds memory access vulnerability in the Linux kernel's ocfs2 filesystem driver. Attackers could exploit this by mountin...

Oct 9, 2024
CVE-2024-45152
7.8

CVE-2024-45152 is an out-of-bounds write vulnerability in Substance3D Stager that allows arbitrary code execution when a user opens a malicious file. ...

Oct 9, 2024
CVE-2024-45141
7.8

CVE-2024-45141 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...

Oct 9, 2024
CVE-2024-45470
7.8

This vulnerability allows remote code execution through specially crafted WRL files in Siemens Teamcenter Visualization and Tecnomatix Plant Simulatio...

Oct 8, 2024
CVE-2024-20092
7.8

This CVE describes an out-of-bounds write vulnerability in the vdec component of MediaTek chipsets, allowing local privilege escalation to System leve...

Oct 7, 2024
CVE-2024-47134
7.8

An out-of-bounds write vulnerability in Kostac PLC Programming Software (formerly Koyo PLC Programming Software) allows attackers to execute arbitrary...

Oct 3, 2024
CVE-2024-46264
7.8

CVE-2024-46264 is a heap buffer overflow vulnerability in cute_png v1.05's cp_find() function that allows attackers to execute arbitrary code or cause...

Oct 1, 2024
CVE-2024-46274
7.8

CVE-2024-46274 is a heap buffer overflow vulnerability in cute_png v1.05's cp_stored() function that allows attackers to execute arbitrary code or cau...

Oct 1, 2024
CVE-2024-46258
7.8

CVE-2024-46258 is a heap buffer overflow vulnerability in cute_png v1.05's cp_load_png_mem() function that allows attackers to execute arbitrary code ...

Oct 1, 2024
CVE-2024-46261
7.8

CVE-2024-46261 is a heap buffer overflow vulnerability in cute_png v1.05's cp_make32() function that allows attackers to execute arbitrary code or cau...

Oct 1, 2024
CVE-2024-46766
7.8

This CVE describes a kernel memory corruption vulnerability in the Intel Ethernet Controller (ice) driver for Linux. It allows out-of-bounds writes wh...

Sep 18, 2024
CVE-2024-44093
7.8

This vulnerability in Android's DRM firmware component allows memory corruption through a logic error in ppmp_unprotect_buf function. It enables local...

Sep 13, 2024
CVE-2024-44095
7.8

This vulnerability allows local attackers to escalate privileges on affected Android devices without requiring user interaction. A logic error in the ...

Sep 13, 2024
CVE-2024-45108
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow an attacker to execute arbitrary code on a victim's system...

Sep 13, 2024
CVE-2024-39384
7.8

CVE-2024-39384 is an out-of-bounds write vulnerability in Adobe Premiere Pro that could allow arbitrary code execution when a user opens a malicious f...

Sep 13, 2024
CVE-2024-39381
7.8

CVE-2024-39381 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Sep 13, 2024
CVE-2024-39377
7.8

Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary cod...

Sep 13, 2024
CVE-2024-45181
7.8

This vulnerability in WibuKey64.sys driver allows attackers to send specially crafted packets that bypass bounds checking, leading to arbitrary addres...

Sep 12, 2024
CVE-2024-45026
7.8

This vulnerability in the Linux kernel's s390/dasd driver for IBM mainframe storage devices can lead to data corruption on Extent Space Efficient (ESE...

Sep 11, 2024
CVE-2023-52916
7.8

A memory overwrite vulnerability in the Linux kernel's media/aspeed driver allows attackers to cause system crashes or potentially execute arbitrary c...

Sep 6, 2024
CVE-2024-44977
7.8

This CVE-2024-44977 is an out-of-bounds write vulnerability in the AMD GPU driver (drm/amdgpu) in the Linux kernel. It occurs when the Trusted Applica...

Sep 4, 2024
CVE-2024-43700
7.8

CVE-2024-43700 is a stack-based buffer overflow vulnerability in xfpt versions before 1.01 that allows arbitrary code execution when processing malici...

Aug 29, 2024
CVE-2024-41879
7.8

CVE-2024-41879 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious...

Aug 26, 2024
CVE-2024-6811
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious WSQ files in IrfanView. Attackers can ga...

Aug 21, 2024
CVE-2024-7305
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious DWF files in AutoCAD. It affec...

Aug 20, 2024
CVE-2024-43839
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's bna driver, where insufficient buffer size for network device names could all...

Aug 17, 2024
CVE-2024-43825
7.8

A Linux kernel vulnerability in the iio subsystem's iio_gts_build_avail_time_table function allows out-of-bounds memory writes when processing zero ti...

Aug 17, 2024
CVE-2024-41840
7.8

Adobe Bridge versions 13.0.8, 14.1.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user op...

Aug 14, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,101 CVEs classified as CWE-787, with 747 rated critical and 2,141 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free