CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,123)
This CVE describes a heap buffer overflow vulnerability in Android's color conversion function that allows local privilege escalation without user int...
Feb 16, 2024This CVE describes a heap buffer overflow vulnerability in Android's ashmem-dev.cpp that allows local privilege escalation without user interaction. A...
Feb 16, 2024This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...
Feb 15, 2024CVE-2024-20728 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious...
Feb 15, 2024Substance3D Painter versions 9.1.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user open...
Feb 15, 2024CVE-2024-20740 is an out-of-bounds write vulnerability in Adobe Substance3D Painter that could allow arbitrary code execution when a user opens a mali...
Feb 15, 2024This vulnerability allows remote code execution through a specially crafted WRL file in Tecnomatix Plant Simulation. Attackers can execute arbitrary c...
Feb 13, 2024This vulnerability allows attackers to cause a heap buffer overflow in Hugin panorama software by parsing a maliciously crafted image file. Attackers ...
Feb 9, 2024This vulnerability in the X.Org server allows out-of-bounds memory access when a frozen device is reattached to a different master device. It can lead...
Feb 9, 2024KiTTY versions 0.76.1.13 and earlier contain a stack-based buffer overflow vulnerability in the username handling code (line 2600) due to insufficient...
Feb 9, 2024This CVE describes an out-of-bounds write vulnerability in Arm Mali GPU kernel drivers that allows a local non-privileged user to perform improper GPU...
Feb 5, 2024CVE-2024-22667 is a stack-based buffer overflow vulnerability in Vim's map.c file where the did_set_langmap function uses sprintf to write to an error...
Feb 5, 2024This vulnerability in GNOME GdkPixbuf allows heap memory corruption when processing specially crafted ANI (Windows animated cursor) files. Attackers c...
Jan 26, 2024CVE-2024-22955 is a stack-buffer-underflow vulnerability in swftools 0.9.2 that allows attackers to read sensitive memory contents or potentially exec...
Jan 19, 2024A stack-buffer-underflow vulnerability in SWFTools v0.9.2 allows attackers to read memory contents beyond allocated buffer boundaries when parsing SWF...
Jan 19, 2024A heap buffer overflow vulnerability in SWFTools v0.9.2 allows remote code execution when processing malicious SWF files. This affects systems running...
Jan 19, 2024CVE-2024-22562 is a stack buffer underflow vulnerability in swftools 0.9.2 that allows attackers to execute arbitrary code or cause denial of service ...
Jan 19, 2024This vulnerability in X.Org server's cursor code allows memory corruption by using incorrect private types in Xephyr and Xwayland, potentially leading...
Jan 18, 2024CVE-2023-50671 is a heap-based buffer overflow vulnerability in exiftags 1.01 that allows writing 28 bytes to an unexpected memory address via the nik...
Jan 11, 2024This is a memory corruption vulnerability (CWE-787) in macOS that allows a malicious application to execute arbitrary code with kernel privileges. It ...
Jan 10, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into processing malicious font files. It affects Apple macOS, iOS, and...
Jan 10, 2024CVE-2023-37420 is an out-of-bounds write vulnerability in GTKWave's VCD parser that allows arbitrary code execution when processing malicious .vcd fil...
Jan 8, 2024CVE-2023-37416 is an out-of-bounds write vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a malicious .vcd file is...
Jan 8, 2024CVE-2023-37418 is an out-of-bounds write vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when processing a malicious ....
Jan 8, 2024CVE-2023-34325 is a stack buffer overflow vulnerability in Xen's libfsimage library, derived from old grub-legacy code. Attackers with access to guest...
Jan 5, 2024This vulnerability in syngo fastView allows attackers to execute arbitrary code by exploiting improper validation of DICOM files. All versions of syng...
Jan 4, 2024This vulnerability in RoyalTSX allows attackers to trigger heap memory corruption and application crashes via specially crafted RTSZ files containing ...
Dec 31, 2023This vulnerability allows remote code execution through a specially crafted DGN file. Attackers can exploit an out-of-bounds write in Open Design Alli...
Dec 26, 2023A stack-based buffer overflow vulnerability in FPWin Pro programming software allows attackers to execute arbitrary code by tricking users into openin...
Dec 19, 2023This vulnerability allows attackers to execute arbitrary code on affected Adobe Substance 3D Designer installations by tricking users into opening mal...
Dec 13, 2023Adobe Substance 3D Sampler versions 4.2.1 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...
Dec 13, 2023Adobe After Effects has an out-of-bounds write vulnerability that allows attackers to execute arbitrary code when a user opens a malicious file. This ...
Dec 13, 2023This CVE describes an out-of-bounds write vulnerability in Adobe Substance 3D Sampler that could allow arbitrary code execution when a user opens a ma...
Dec 13, 2023Adobe Substance 3D Sampler versions 4.2.1 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...
Dec 13, 2023This vulnerability in xorg-server allows out-of-bounds memory reads and writes when querying or changing XKB button actions, such as switching from to...
Dec 13, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow attackers to execute arbitrary code or cause application crashes by tri...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS's AppleGVA framework that could allow arbitrary code execution when processing malicious...
Dec 12, 2023This vulnerability in macOS AppleVADriver allows out-of-bounds write when processing images, potentially leading to arbitrary code execution. Attacker...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...
Dec 12, 2023This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...
Dec 12, 2023This vulnerability allows local attackers to write beyond allocated memory bounds in the Pixel GPU driver, potentially leading to kernel-level privile...
Dec 8, 2023This CVE describes an out-of-bounds write vulnerability in Android's Bluetooth stack (btm_ble_gap.cc) that allows local privilege escalation. Attacker...
Dec 4, 2023This vulnerability in Android's Bluetooth stack allows local attackers to escalate privileges without user interaction. An out-of-bounds write in the ...
Dec 4, 2023This vulnerability allows local privilege escalation on Android devices through memory corruption in the IncidentService component. An attacker could ...
Dec 4, 2023This CVE describes a critical Bluetooth stack vulnerability in Android's Bluetooth Low Energy (BLE) implementation. An out-of-bounds write due to a lo...
Dec 4, 2023This CVE describes a memory corruption vulnerability in MediaTek audio components where missing bounds checks allow out-of-bounds writes. Attackers ca...
Dec 4, 2023This CVE describes an integer overflow vulnerability in a decoder component that could lead to out-of-bounds write. Successful exploitation could allo...
Dec 4, 2023About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,123 CVEs classified as CWE-787, with 750 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free