CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,122
Total CVEs
749
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,122)

CVE-2024-39381
7.8

CVE-2024-39381 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Sep 13, 2024
CVE-2024-39377
7.8

Adobe Media Encoder versions 24.5, 23.6.8 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary cod...

Sep 13, 2024
CVE-2024-45181
7.8

This vulnerability in WibuKey64.sys driver allows attackers to send specially crafted packets that bypass bounds checking, leading to arbitrary addres...

Sep 12, 2024
CVE-2024-45026
7.8

This vulnerability in the Linux kernel's s390/dasd driver for IBM mainframe storage devices can lead to data corruption on Extent Space Efficient (ESE...

Sep 11, 2024
CVE-2023-52916
7.8

A memory overwrite vulnerability in the Linux kernel's media/aspeed driver allows attackers to cause system crashes or potentially execute arbitrary c...

Sep 6, 2024
CVE-2024-44977
7.8

This CVE-2024-44977 is an out-of-bounds write vulnerability in the AMD GPU driver (drm/amdgpu) in the Linux kernel. It occurs when the Trusted Applica...

Sep 4, 2024
CVE-2024-43700
7.8

CVE-2024-43700 is a stack-based buffer overflow vulnerability in xfpt versions before 1.01 that allows arbitrary code execution when processing malici...

Aug 29, 2024
CVE-2024-41879
7.8

CVE-2024-41879 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious...

Aug 26, 2024
CVE-2024-6811
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious WSQ files in IrfanView. Attackers can ga...

Aug 21, 2024
CVE-2024-7305
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious DWF files in AutoCAD. It affec...

Aug 20, 2024
CVE-2024-43839
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's bna driver, where insufficient buffer size for network device names could all...

Aug 17, 2024
CVE-2024-43825
7.8

A Linux kernel vulnerability in the iio subsystem's iio_gts_build_avail_time_table function allows out-of-bounds memory writes when processing zero ti...

Aug 17, 2024
CVE-2024-41840
7.8

Adobe Bridge versions 13.0.8, 14.1.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user op...

Aug 14, 2024
CVE-2024-39423
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...

Aug 14, 2024
CVE-2024-39390
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file...

Aug 14, 2024
CVE-2024-34133
7.8

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code ...

Aug 14, 2024
CVE-2024-34124
7.8

Adobe Dimension versions 3.4.11 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens a...

Aug 14, 2024
CVE-2024-41864
7.8

CVE-2024-41864 is an out-of-bounds write vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a malicious...

Aug 14, 2024
CVE-2024-34622
7.8

This vulnerability allows local attackers to write data beyond intended memory boundaries in Samsung Notes, potentially enabling arbitrary code execut...

Aug 7, 2024
CVE-2024-42086
7.8

This CVE addresses integer overflow vulnerabilities in the BME680 sensor driver's compensation functions within the Linux kernel. Attackers could expl...

Jul 29, 2024
CVE-2024-4081
7.8

A memory corruption vulnerability in NI LabVIEW due to improper length checks could allow information disclosure or arbitrary code execution when user...

Jul 23, 2024
CVE-2024-40724
7.8

A heap-based buffer overflow vulnerability in Assimp (Open Asset Import Library) allows local attackers to execute arbitrary code by processing specia...

Jul 19, 2024
CVE-2022-48847
7.8

This is an out-of-bounds write vulnerability in the Linux kernel's watch_queue subsystem due to improper bounds checking. Attackers with local access ...

Jul 16, 2024
CVE-2024-41003
7.8

This CVE-2024-41003 is a Linux kernel vulnerability in the BPF verifier component that can lead to privilege escalation. The flaw allows corruption of...

Jul 12, 2024
CVE-2024-40974
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's powerpc/pseries hypercall functions. The vulnerability allows stack corruptio...

Jul 12, 2024
CVE-2024-31313
7.8

This vulnerability in Android's Fast Message Queue (FMQ) library allows an out-of-bounds write due to incorrect bounds checking in the availableToWrit...

Jul 9, 2024
CVE-2024-20782
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious file...

Jul 9, 2024
CVE-2024-32056
7.8

This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting an out-of-bounds write buffer overflow when parsing mal...

Jul 9, 2024
CVE-2022-25480
7.8

This vulnerability in Realtek card reader drivers allows attackers to write beyond allocated kernel memory buffers, potentially leading to privilege e...

Jul 2, 2024
CVE-2024-4467
7.8

A vulnerability in QEMU's qemu-img utility allows attackers to cause denial of service or potentially read/write to external files by providing a spec...

Jul 2, 2024
CVE-2024-37006
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPRODUCT files in affected Autodesk applicati...

Jun 25, 2024
CVE-2024-23156
7.8

A memory corruption vulnerability in Autodesk applications allows attackers to execute arbitrary code by tricking users into opening malicious 3DM fil...

Jun 25, 2024
CVE-2024-23150
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking users into opening malicious PRT files in Autodesk AutoCAD....

Jun 25, 2024
CVE-2024-23146
7.8

This vulnerability allows attackers to execute arbitrary code or cause crashes by tricking AutoCAD into processing malicious X_B and X_T files. It aff...

Jun 25, 2024
CVE-2024-23148
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious CATPRODUCT files in affected Autodesk applicati...

Jun 25, 2024
CVE-2024-37000
7.8

A memory corruption vulnerability in Autodesk's pskernel.DLL allows attackers to execute arbitrary code by tricking users into opening malicious X_B f...

Jun 25, 2024
CVE-2024-23144
7.8

This vulnerability allows attackers to execute arbitrary code on AutoCAD systems by tricking users into opening malicious CATPART files. It affects Au...

Jun 25, 2024
CVE-2022-48744
7.8

This vulnerability in the Linux kernel's mlx5e network driver involves a buffer overflow due to improper memory copying across structure fields. Attac...

Jun 20, 2024
CVE-2022-48712
7.8

A memory corruption vulnerability in the Linux kernel's ext4 filesystem fast commit feature. When krealloc() fails in ext4_fc_record_modified_inode(),...

Jun 20, 2024
CVE-2024-37022
7.8

This vulnerability in Fuji Electric Tellus Lite V-Simulator allows an attacker to write data beyond intended memory boundaries, potentially leading to...

Jun 13, 2024
CVE-2024-34115
7.8

CVE-2024-34115 is an out-of-bounds write vulnerability in Adobe Substance3D Stager that could allow arbitrary code execution when a user opens a malic...

Jun 13, 2024
CVE-2024-27815
7.8

This CVE describes an out-of-bounds write vulnerability in Apple operating systems that allows an app to execute arbitrary code with kernel privileges...

Jun 10, 2024
CVE-2024-27831
7.8

This CVE describes an out-of-bounds write vulnerability in Apple operating systems that could allow an attacker to execute arbitrary code or cause app...

Jun 10, 2024
CVE-2022-32897
7.8

This vulnerability allows attackers to execute arbitrary code on macOS systems by tricking users into opening malicious TIFF image files. It affects m...

Jun 10, 2024
CVE-2024-5304
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious TGA files in Kofax Power PDF. The flaw e...

Jun 6, 2024
CVE-2024-30373
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPF files in Kofax Power PDF. The flaw e...

Jun 6, 2024
CVE-2024-5303
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSD files in Kofax Power PDF. The flaw e...

Jun 6, 2024
CVE-2024-30374
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious KSP files in Luxion KeyShot Viewer. The ...

Jun 6, 2024
CVE-2024-36934
7.8

This CVE-2024-36934 is a Linux kernel vulnerability in the bna driver where improper memory handling allows out-of-bounds read. Attackers could exploi...

May 30, 2024
CVE-2024-36906
7.8

A KASAN (Kernel Address SANitizer) stack poisoning vulnerability in the ARM Linux kernel allows stale poison values to remain in stack memory after CP...

May 30, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,122 CVEs classified as CWE-787, with 749 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free