CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,123
Total CVEs
750
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
96
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,123)

CVE-2023-38081
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-38083
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-37345
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-37349
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-37339
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PCX files in Kofax Power PDF. Attackers ...

May 3, 2024
CVE-2023-37341
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files in Kofax Power PDF. The flaw e...

May 3, 2024
CVE-2023-37343
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Kofax Power PDF. Atta...

May 3, 2024
CVE-2023-37337
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Kofax Power PDF. Atta...

May 3, 2024
CVE-2023-34291
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_...

May 3, 2024
CVE-2023-34273
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fatek Automation FvDesigner installations by tricking users into opening malic...

May 3, 2024
CVE-2023-34267
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fatek Automation FvDesigner installations by tricking users into opening malic...

May 3, 2024
CVE-2023-34269
7.8

This vulnerability allows remote attackers to execute arbitrary code on Fatek Automation FvDesigner installations by tricking users into opening malic...

May 3, 2024
CVE-2023-34271
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Fatek Automation FvDesigner software by tricking users into op...

May 3, 2024
CVE-2023-27343
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious EMF files. Attacke...

May 3, 2024
CVE-2023-27345
7.8

CVE-2023-27345 is a remote code execution vulnerability in PDF-XChange Editor caused by an out-of-bounds write during PDF file parsing. Attackers can ...

May 3, 2024
CVE-2023-27339
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNG files in PDF-XChange Editor. The fla...

May 3, 2024
CVE-2023-27341
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious TIF files in PDF-XChange Editor. The fla...

May 3, 2024
CVE-2024-27036
7.8

A writeback data corruption vulnerability in the Linux kernel's CIFS filesystem implementation allows attackers to corrupt files written to CIFS share...

May 1, 2024
CVE-2024-26988
7.8

A memory overflow vulnerability in the Linux kernel's initialization code could allow attackers to corrupt kernel memory by providing specially crafte...

May 1, 2024
CVE-2022-48632
7.8

This CVE describes a stack buffer overflow vulnerability in the Linux kernel's i2c-mlxbf driver. An attacker could exploit this to crash the system or...

Apr 28, 2024
CVE-2024-26842
7.8

This CVE describes an integer overflow vulnerability in the Linux kernel's UFS (Universal Flash Storage) driver. When task_tag values exceed 31 in MCQ...

Apr 17, 2024
CVE-2024-30271
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious f...

Apr 11, 2024
CVE-2023-52351
7.8

This vulnerability in the RIL (Radio Interface Layer) service allows local attackers with system privileges to perform out-of-bounds writes, potential...

Apr 8, 2024
CVE-2024-29752
7.8

This vulnerability allows local privilege escalation on affected Android devices through an out-of-bounds write in the tmu.c component. Attackers can ...

Apr 5, 2024
CVE-2024-3298
7.8

CVE-2024-3298 allows attackers to execute arbitrary code by exploiting out-of-bounds write and type confusion vulnerabilities in eDrawings when openin...

Apr 4, 2024
CVE-2024-27339
7.8

This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw e...

Apr 3, 2024
CVE-2024-26736
7.8

This CVE describes a buffer overflow vulnerability in the Linux kernel's AFS (Andrew File System) implementation. An attacker could exploit this to ca...

Apr 3, 2024
CVE-2024-26742
7.8

A bug in the Linux kernel's smartpqi SCSI driver causes a kernel warning and potential undefined behavior when the disable_managed_interrupts module p...

Apr 3, 2024
CVE-2024-26753
7.8

This CVE describes a stack overflow vulnerability in the Linux kernel's virtio crypto asymmetric cipher (akcipher) driver. A memory copy operation cop...

Apr 3, 2024
CVE-2024-30355
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

Apr 2, 2024
CVE-2024-30348
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...

Apr 2, 2024
CVE-2024-27327
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The fla...

Apr 1, 2024
CVE-2024-21912
7.8

A memory corruption vulnerability in Rockwell Automation Arena Simulation allows arbitrary code execution when a user opens a malicious file. Attacker...

Mar 26, 2024
CVE-2021-47148
7.8

A buffer overflow vulnerability in the Linux kernel's octeontx2-pf driver allows local attackers to corrupt kernel memory. This affects systems using ...

Mar 25, 2024
CVE-2024-20761
7.8

Adobe Animate versions 24.0, 23.0.3 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user ope...

Mar 18, 2024
CVE-2024-20756
7.8

CVE-2024-20756 is an out-of-bounds write vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious file. T...

Mar 18, 2024
CVE-2024-27221
7.8

CVE-2024-27221 is an out-of-bounds write vulnerability in Android's update_policy_data function that allows local privilege escalation without user in...

Mar 11, 2024
CVE-2024-26610
7.8

This CVE describes a memory corruption vulnerability in the Linux kernel's iwlwifi driver, which handles Intel wireless network adapters. An attacker ...

Mar 11, 2024
CVE-2023-52494
7.8

This CVE addresses an alignment vulnerability in the Linux kernel's MHI host bus driver where an unaligned event ring read pointer could cause denial ...

Mar 11, 2024
CVE-2024-1696
7.8

This vulnerability allows local attackers to execute arbitrary code by exploiting an out-of-bounds write when a user opens a malicious DCM file in San...

Mar 11, 2024
CVE-2024-0050
7.8

This CVE describes an out-of-bounds write vulnerability in Android's SoftVideoDecoderOMXComponent that could allow local privilege escalation or code ...

Mar 11, 2024
CVE-2024-23611
7.8

An out-of-bounds write vulnerability in LabVIEW allows remote code execution when a user opens a specially crafted VI file. This affects LabVIEW 2024 ...

Mar 11, 2024
CVE-2024-23265
7.8

This is a memory corruption vulnerability in Apple operating systems that allows malicious apps to cause system crashes or write to kernel memory. It ...

Mar 8, 2024
CVE-2024-23270
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Mar 8, 2024
CVE-2024-23225
7.8

This CVE describes a memory corruption vulnerability in Apple iOS/iPadOS kernel that allows attackers with kernel read/write capabilities to bypass me...

Mar 5, 2024
CVE-2024-23296
7.8

CVE-2024-23296 is a memory corruption vulnerability in Apple's iOS/iPadOS kernel that allows attackers with kernel read/write capabilities to bypass m...

Mar 5, 2024
CVE-2024-25578
7.8

MicroDicom DICOM Viewer versions 2023.3 and earlier contain a memory corruption vulnerability due to improper input validation. This could allow attac...

Mar 1, 2024
CVE-2023-52482
7.8

This CVE addresses a speculative return stack overflow (SRSO) vulnerability in the Linux kernel affecting Hygon processors. It allows attackers to pot...

Feb 29, 2024
CVE-2023-42848
7.8

This vulnerability allows an attacker to cause heap corruption by tricking a user into processing a maliciously crafted image. It affects Apple device...

Feb 21, 2024
CVE-2023-42873
7.8

This is a kernel privilege escalation vulnerability in Apple operating systems where an application can bypass bounds checks to execute arbitrary code...

Feb 21, 2024

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,123 CVEs classified as CWE-787, with 750 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free