CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,122
Total CVEs
749
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
95
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,122)

CVE-2024-36895
7.8

A buffer overflow vulnerability in the Linux kernel's USB gadget UVC driver allows attackers to write beyond allocated memory bounds when parsing conf...

May 30, 2024
CVE-2021-47566
7.8

A kernel memory corruption vulnerability in the Linux kernel's vmcore handling code allows local attackers to trigger a kernel panic (crash) by exploi...

May 24, 2024
CVE-2021-47536
7.8

This is a memory corruption vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem where smc_lgr_cleanup_early() incorrectly...

May 24, 2024
CVE-2024-30279
7.8

CVE-2024-30279 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious...

May 23, 2024
CVE-2021-47496
7.8

A Linux kernel vulnerability in the TLS implementation where incorrect error sign handling leads to memory corruption. This allows local attackers to ...

May 22, 2024
CVE-2021-47489
7.8

This CVE describes an out-of-bounds write vulnerability in the AMD GPU driver (amdgpu) debugfs interface in the Linux kernel. Attackers with local acc...

May 22, 2024
CVE-2021-47475
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's vmk80xx comedi driver for USB data acquisition devices. Attackers could explo...

May 22, 2024
CVE-2021-47477
7.8

This CVE describes a kernel vulnerability in the comedi dt9812 driver where USB transfer buffers were allocated on the stack instead of proper DMA buf...

May 22, 2024
CVE-2021-47458
7.8

A buffer overflow vulnerability in the Linux kernel's OCFS2 filesystem driver allows local attackers to trigger a kernel panic (denial of service) whe...

May 22, 2024
CVE-2023-52864
7.8

A memory corruption vulnerability in the Linux kernel's WMI (Windows Management Instrumentation) subsystem allows local attackers to potentially escal...

May 21, 2024
CVE-2023-52868
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's thermal subsystem. The vulnerability occurs when sprintf() functions attempt ...

May 21, 2024
CVE-2023-52816
7.8

This CVE describes a shift out-of-bounds vulnerability in the AMD GPU kernel driver (drm/amdkfd) in the Linux kernel. It allows local attackers to cau...

May 21, 2024
CVE-2023-52796
7.8

This CVE describes a stack overflow vulnerability in the Linux kernel's ipvlan network driver when processing IPv6 outbound traffic. It affects system...

May 21, 2024
CVE-2023-52775
7.8

A race condition in the Linux kernel's SMC-R (Shared Memory Communications over RDMA) implementation causes data corruption when applications receive ...

May 21, 2024
CVE-2023-52764
7.8

This CVE describes a shift-out-of-bounds vulnerability in the Linux kernel's gspca cpia1 camera driver. When the 'sd->params.exposure.gain' variable e...

May 21, 2024
CVE-2023-52748
7.8

This CVE is a buffer overflow vulnerability in the Linux kernel's F2FS filesystem compression module. An attacker could exploit this to cause a kernel...

May 21, 2024
CVE-2021-47404
7.8

A memory corruption vulnerability in the Linux kernel's HID betop driver allows attackers to write beyond allocated memory boundaries. This affects Li...

May 21, 2024
CVE-2021-47352
7.8

This CVE addresses a vulnerability in the Linux kernel's virtio-net driver where insufficient validation of 'used length' values from untrusted virtua...

May 21, 2024
CVE-2021-47282
7.8

This vulnerability in the Linux kernel's bcm2835 SPI driver allows out-of-bounds memory access when more than 3 SPI slave devices are configured using...

May 21, 2024
CVE-2021-47286
7.8

A vulnerability in the Linux kernel's MHI (Mobile Host Interface) bus subsystem allows out-of-bounds memory access when processing command completions...

May 21, 2024
CVE-2024-36001
7.8

A race condition vulnerability in the Linux kernel's netfs subsystem when writing to files in writethrough mode can cause kernel warnings and potentia...

May 20, 2024
CVE-2023-52669
7.8

This CVE describes a buffer overread vulnerability in the Linux kernel's s390 AES CTR mode implementation. When processing the final block of data, th...

May 17, 2024
CVE-2024-30292
7.8

CVE-2024-30292 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...

May 16, 2024
CVE-2024-30290
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Framemaker that could allow an attacker to execute arbitrary code on the victim's sys...

May 16, 2024
CVE-2024-30296
7.8

Adobe Animate versions 24.0.2, 23.0.5 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user o...

May 16, 2024
CVE-2024-30307
7.8

Substance3D Painter versions 9.1.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a ...

May 16, 2024
CVE-2024-30282
7.8

Adobe Animate versions 24.0.2, 23.0.5 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on...

May 16, 2024
CVE-2024-30310
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...

May 15, 2024
CVE-2024-34086
7.8

This vulnerability allows remote code execution through specially crafted CGM files in Siemens JT2Go and Teamcenter Visualization software. An attacke...

May 14, 2024
CVE-2024-32639
7.8

This vulnerability allows remote code execution through a buffer overflow when parsing malicious MODEL files in Tecnomatix Plant Simulation. Attackers...

May 14, 2024
CVE-2024-31980
7.8

This vulnerability in Siemens Parasolid allows remote code execution when processing malicious X_T part files. An out-of-bounds write vulnerability en...

May 14, 2024
CVE-2022-43653
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Bentley View. Attackers can...

May 7, 2024
CVE-2023-49675
7.8

CVE-2023-49675 is an out-of-bounds write vulnerability in certain project file handling software. An unauthenticated attacker can trick users into ope...

May 6, 2024
CVE-2023-51597
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious U3D files in Kofax Power PDF. Attackers ...

May 3, 2024
CVE-2023-51569
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious BMP files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-50190
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. Th...

May 3, 2024
CVE-2023-42127
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-42071
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in PDF-XChange Editor. The fla...

May 3, 2024
CVE-2023-42051
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U...

May 3, 2024
CVE-2023-40481
7.8

This vulnerability in 7-Zip allows remote attackers to execute arbitrary code by tricking users into opening malicious SquashFS (SQFS) archive files. ...

May 3, 2024
CVE-2023-40483
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Maxon Cinema 4D. The flaw e...

May 3, 2024
CVE-2023-39502
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected PDF-XChange Editor installations by tricking users into opening malic...

May 3, 2024
CVE-2023-39498
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-39500
7.8

CVE-2023-39500 is a remote code execution vulnerability in PDF-XChange Editor's JPG file parsing. Attackers can exploit this by tricking users into op...

May 3, 2024
CVE-2023-39490
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening a malicious PDF file. The fl...

May 3, 2024
CVE-2023-39485
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-38087
7.8

This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visiting...

May 3, 2024
CVE-2023-38089
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Kofax Power PDF installations by tricking users into opening maliciou...

May 3, 2024
CVE-2023-38079
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Kofax Power PDF. Atta...

May 3, 2024
CVE-2023-38081
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Kofax Power PDF. The flaw e...

May 3, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,122 CVEs classified as CWE-787, with 749 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free