CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,123
Total CVEs
750
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
96
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,123)

CVE-2024-0018
7.8

This CVE describes a heap buffer overflow vulnerability in Android's color conversion function that allows local privilege escalation without user int...

Feb 16, 2024
CVE-2024-0033
7.8

This CVE describes a heap buffer overflow vulnerability in Android's ashmem-dev.cpp that allows local privilege escalation without user interaction. A...

Feb 16, 2024
CVE-2024-20726
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...

Feb 15, 2024
CVE-2024-20728
7.8

CVE-2024-20728 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious...

Feb 15, 2024
CVE-2024-20744
7.8

Substance3D Painter versions 9.1.1 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user open...

Feb 15, 2024
CVE-2024-20740
7.8

CVE-2024-20740 is an out-of-bounds write vulnerability in Adobe Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Feb 15, 2024
CVE-2024-23795
7.8

This vulnerability allows remote code execution through a specially crafted WRL file in Tecnomatix Plant Simulation. Attackers can execute arbitrary c...

Feb 13, 2024
CVE-2024-25442
7.8

This vulnerability allows attackers to cause a heap buffer overflow in Hugin panorama software by parsing a maliciously crafted image file. Attackers ...

Feb 9, 2024
CVE-2024-0229
7.8

This vulnerability in the X.Org server allows out-of-bounds memory access when a frozen device is reattached to a different master device. It can lead...

Feb 9, 2024
CVE-2024-25004
7.8

KiTTY versions 0.76.1.13 and earlier contain a stack-based buffer overflow vulnerability in the username handling code (line 2600) due to insufficient...

Feb 9, 2024
CVE-2023-5643
7.8

This CVE describes an out-of-bounds write vulnerability in Arm Mali GPU kernel drivers that allows a local non-privileged user to perform improper GPU...

Feb 5, 2024
CVE-2024-22667
7.8

CVE-2024-22667 is a stack-based buffer overflow vulnerability in Vim's map.c file where the did_set_langmap function uses sprintf to write to an error...

Feb 5, 2024
CVE-2022-48622
7.8

This vulnerability in GNOME GdkPixbuf allows heap memory corruption when processing specially crafted ANI (Windows animated cursor) files. Attackers c...

Jan 26, 2024
CVE-2024-22955
7.8

CVE-2024-22955 is a stack-buffer-underflow vulnerability in swftools 0.9.2 that allows attackers to read sensitive memory contents or potentially exec...

Jan 19, 2024
CVE-2024-22911
7.8

A stack-buffer-underflow vulnerability in SWFTools v0.9.2 allows attackers to read memory contents beyond allocated buffer boundaries when parsing SWF...

Jan 19, 2024
CVE-2024-22913
7.8

A heap buffer overflow vulnerability in SWFTools v0.9.2 allows remote code execution when processing malicious SWF files. This affects systems running...

Jan 19, 2024
CVE-2024-22562
7.8

CVE-2024-22562 is a stack buffer underflow vulnerability in swftools 0.9.2 that allows attackers to execute arbitrary code or cause denial of service ...

Jan 19, 2024
CVE-2024-0409
7.8

This vulnerability in X.Org server's cursor code allows memory corruption by using incorrect private types in Xephyr and Xwayland, potentially leading...

Jan 18, 2024
CVE-2023-50671
7.8

CVE-2023-50671 is a heap-based buffer overflow vulnerability in exiftags 1.01 that allows writing 28 bytes to an unexpected memory address via the nik...

Jan 11, 2024
CVE-2022-46721
7.8

This is a memory corruption vulnerability (CWE-787) in macOS that allows a malicious application to execute arbitrary code with kernel privileges. It ...

Jan 10, 2024
CVE-2023-32366
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing malicious font files. It affects Apple macOS, iOS, and...

Jan 10, 2024
CVE-2023-37420
7.8

CVE-2023-37420 is an out-of-bounds write vulnerability in GTKWave's VCD parser that allows arbitrary code execution when processing malicious .vcd fil...

Jan 8, 2024
CVE-2023-37416
7.8

CVE-2023-37416 is an out-of-bounds write vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when a malicious .vcd file is...

Jan 8, 2024
CVE-2023-37418
7.8

CVE-2023-37418 is an out-of-bounds write vulnerability in GTKWave's VCD file parser that allows arbitrary code execution when processing a malicious ....

Jan 8, 2024
CVE-2023-34325
7.8

CVE-2023-34325 is a stack buffer overflow vulnerability in Xen's libfsimage library, derived from old grub-legacy code. Attackers with access to guest...

Jan 5, 2024
CVE-2021-40367
7.8

This vulnerability in syngo fastView allows attackers to execute arbitrary code by exploiting improper validation of DICOM files. All versions of syng...

Jan 4, 2024
CVE-2023-52277
7.8

This vulnerability in RoyalTSX allows attackers to trigger heap memory corruption and application crashes via specially crafted RTSZ files containing ...

Dec 31, 2023
CVE-2023-5180
7.8

This vulnerability allows remote code execution through a specially crafted DGN file. Attackers can exploit an out-of-bounds write in Open Design Alli...

Dec 26, 2023
CVE-2023-6314
7.8

A stack-based buffer overflow vulnerability in FPWin Pro programming software allows attackers to execute arbitrary code by tricking users into openin...

Dec 19, 2023
CVE-2023-48639
7.8

This vulnerability allows attackers to execute arbitrary code on affected Adobe Substance 3D Designer installations by tricking users into opening mal...

Dec 13, 2023
CVE-2023-48629
7.8

Adobe Substance 3D Sampler versions 4.2.1 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...

Dec 13, 2023
CVE-2023-48632
7.8

Adobe After Effects has an out-of-bounds write vulnerability that allows attackers to execute arbitrary code when a user opens a malicious file. This ...

Dec 13, 2023
CVE-2023-48625
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Substance 3D Sampler that could allow arbitrary code execution when a user opens a ma...

Dec 13, 2023
CVE-2023-48627
7.8

Adobe Substance 3D Sampler versions 4.2.1 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user op...

Dec 13, 2023
CVE-2023-6377
7.8

This vulnerability in xorg-server allows out-of-bounds memory reads and writes when querying or changing XKB button actions, such as switching from to...

Dec 13, 2023
CVE-2023-42905
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...

Dec 12, 2023
CVE-2023-42907
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...

Dec 12, 2023
CVE-2023-42909
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow attackers to execute arbitrary code or cause application crashes by tri...

Dec 12, 2023
CVE-2023-42911
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...

Dec 12, 2023
CVE-2023-42926
7.8

This CVE describes memory corruption vulnerabilities in macOS's AppleGVA framework that could allow arbitrary code execution when processing malicious...

Dec 12, 2023
CVE-2023-42882
7.8

This vulnerability in macOS AppleVADriver allows out-of-bounds write when processing images, potentially leading to arbitrary code execution. Attacker...

Dec 12, 2023
CVE-2023-42901
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...

Dec 12, 2023
CVE-2023-42903
7.8

This CVE describes memory corruption vulnerabilities in macOS that could allow arbitrary code execution when processing malicious files. Attackers cou...

Dec 12, 2023
CVE-2023-48421
7.8

This vulnerability allows local attackers to write beyond allocated memory bounds in the Pixel GPU driver, potentially leading to kernel-level privile...

Dec 8, 2023
CVE-2023-45773
7.8

This CVE describes an out-of-bounds write vulnerability in Android's Bluetooth stack (btm_ble_gap.cc) that allows local privilege escalation. Attacker...

Dec 4, 2023
CVE-2023-45775
7.8

This vulnerability in Android's Bluetooth stack allows local attackers to escalate privileges without user interaction. An out-of-bounds write in the ...

Dec 4, 2023
CVE-2023-40091
7.8

This vulnerability allows local privilege escalation on Android devices through memory corruption in the IncidentService component. An attacker could ...

Dec 4, 2023
CVE-2023-40080
7.8

This CVE describes a critical Bluetooth stack vulnerability in Android's Bluetooth Low Energy (BLE) implementation. An out-of-bounds write due to a lo...

Dec 4, 2023
CVE-2023-32847
7.8

This CVE describes a memory corruption vulnerability in MediaTek audio components where missing bounds checks allow out-of-bounds writes. Attackers ca...

Dec 4, 2023
CVE-2023-32850
7.8

This CVE describes an integer overflow vulnerability in a decoder component that could lead to out-of-bounds write. Successful exploitation could allo...

Dec 4, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,123 CVEs classified as CWE-787, with 750 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free