CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,123
Total CVEs
750
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
96
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,123)

CVE-2023-5593
7.8

An out-of-bounds write vulnerability in Zyxel SecuExtender SSL VPN Client version 4.0.4.0 allows authenticated local users to escalate privileges by s...

Nov 20, 2023
CVE-2023-47073
7.8

Adobe After Effects versions 24.0.2 and earlier, and 23.6 and earlier, contain an out-of-bounds write vulnerability that could allow attackers to exec...

Nov 17, 2023
CVE-2023-47070
7.8

Adobe After Effects versions 24.0.2 and earlier, and 23.6 and earlier, contain an out-of-bounds write vulnerability that could allow attackers to exec...

Nov 17, 2023
CVE-2023-44330
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow an attacker to execute arbitrary code on a victim's system...

Nov 16, 2023
CVE-2023-47470
7.8

A buffer overflow vulnerability in FFmpeg's ref_pic_list_struct function allows remote attackers to write outside array bounds, potentially executing ...

Nov 16, 2023
CVE-2023-48014
7.8

This CVE describes a stack overflow vulnerability in GPAC's HEVC video parser that could allow remote code execution. Attackers could exploit this by ...

Nov 15, 2023
CVE-2023-47584
7.8

This CVE describes an out-of-bounds write vulnerability in V-Server and V-Server Lite software versions up to 4.0.18.0. Attackers can exploit this by ...

Nov 15, 2023
CVE-2023-47586
7.8

This vulnerability allows attackers to execute arbitrary code or disclose sensitive information by tricking users into opening malicious VPR files. It...

Nov 15, 2023
CVE-2023-32837
7.8

This vulnerability is an out-of-bounds write in a MediaTek JPEG driver that allows local privilege escalation without user interaction. Attackers can ...

Nov 6, 2023
CVE-2023-40128
7.8

This CVE describes a heap buffer overflow vulnerability in libxml2's xmlregexp.c functions, allowing out-of-bounds writes. It enables local privilege ...

Oct 27, 2023
CVE-2023-5367
7.8

This CVE-2023-5367 is an out-of-bounds write vulnerability in xorg-x11-server that allows attackers to write beyond allocated heap buffers. It could l...

Oct 25, 2023
CVE-2022-3699
7.8

This is a local privilege escalation vulnerability in Lenovo HardwareScanPlugin and Lenovo Diagnostics software. A local user with limited privileges ...

Oct 25, 2023
CVE-2023-39431
7.8

CVE-2023-39431 is an out-of-bounds write vulnerability in Sante DICOM Viewer Pro due to improper validation of user-supplied DICOM files, allowing arb...

Oct 19, 2023
CVE-2023-31096
7.8

This vulnerability allows local attackers to escalate privileges from medium-integrity processes to SYSTEM via a stack overflow in the Broadcom LSI PC...

Oct 10, 2023
CVE-2023-44082
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Oct 10, 2023
CVE-2023-30733
7.8

A stack-based buffer overflow vulnerability in Samsung's HDCP trustlet allows local privileged attackers to execute arbitrary code. This affects Samsu...

Oct 4, 2023
CVE-2023-43361
7.8

A buffer overflow vulnerability in Vorbis-tools v1.4.2 allows local attackers to execute arbitrary code or cause denial of service when converting WAV...

Oct 2, 2023
CVE-2023-26369
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...

Sep 13, 2023
CVE-2023-41032
7.8

This vulnerability allows remote code execution through specially crafted X_T files in Parasolid and Simcenter Femap software. An attacker could execu...

Sep 12, 2023
CVE-2022-28831
7.8

Adobe InDesign versions 17.1 and earlier (macOS/Windows) and 16.4.1 and earlier (macOS/Windows) contain an out-of-bounds write vulnerability that coul...

Sep 11, 2023
CVE-2022-28833
7.8

Adobe InDesign versions 17.1 and earlier (macOS/Windows) and 16.4.1 and earlier (macOS/Windows) contain an out-of-bounds write vulnerability. When exp...

Sep 11, 2023
CVE-2022-30646
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious f...

Sep 7, 2023
CVE-2022-30642
7.8

CVE-2022-30642 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious fi...

Sep 7, 2023
CVE-2023-39985
7.8

CVE-2023-39985 is an out-of-bounds write vulnerability in Hitachi EH-VIEW (Designer) that allows local attackers to potentially execute arbitrary code...

Aug 23, 2023
CVE-2023-3495
7.8

This is an out-of-bounds write vulnerability in Hitachi EH-VIEW (KeypadDesigner) that allows local attackers to potentially execute arbitrary code. Us...

Aug 23, 2023
CVE-2023-34853
7.8

A buffer overflow vulnerability in Supermicro X12DPG-QR motherboard BIOS version 1.4b allows local attackers to execute arbitrary code by manipulating...

Aug 22, 2023
CVE-2022-44840
7.8

A heap buffer overflow vulnerability in binutils readelf allows attackers to execute arbitrary code or cause denial of service by providing specially ...

Aug 22, 2023
CVE-2022-47069
7.8

This vulnerability in p7zip 16.02 involves an out-of-bounds read in the ZIP archive parsing code. Attackers could potentially cause crashes or read un...

Aug 22, 2023
CVE-2020-21724
7.8

A buffer overflow vulnerability in the ExtractorInformation function of oggvideotools allows remote attackers to execute arbitrary code by tricking a ...

Aug 22, 2023
CVE-2020-18831
7.8

A buffer overflow vulnerability in Exiv2's PNG processing allows remote attackers to cause denial of service or potentially execute arbitrary code by ...

Aug 22, 2023
CVE-2023-39181
7.8

This vulnerability in Solid Edge SE2023 allows attackers to execute arbitrary code by exploiting an out-of-bounds write buffer overflow when parsing m...

Aug 8, 2023
CVE-2023-38680
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Aug 8, 2023
CVE-2023-38747
7.8

A heap-based buffer overflow vulnerability in CX-Programmer software allows attackers to execute arbitrary code or disclose sensitive information by t...

Aug 3, 2023
CVE-2023-3812
7.8

This vulnerability allows a local user to trigger an out-of-bounds memory access in the Linux kernel's TUN/TAP device driver by sending malicious over...

Jul 24, 2023
CVE-2023-3611
7.8

This CVE-2023-3611 is an out-of-bounds write vulnerability in the Linux kernel's QFQ scheduler component that allows local attackers to escalate privi...

Jul 21, 2023
CVE-2021-39822
7.8

Adobe InDesign has an out-of-bounds write vulnerability in BMP file parsing that allows arbitrary code execution when a user opens a malicious BMP fil...

Jul 20, 2023
CVE-2021-34119
7.8

CVE-2021-34119 is a heap-based buffer overflow vulnerability in HTMLDOC's parse_paragraph function that allows remote code execution or denial of serv...

Jul 18, 2023
CVE-2023-29308
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system....

Jul 12, 2023
CVE-2023-37248
7.8

This vulnerability allows remote code execution through an out-of-bounds write buffer overflow when parsing malicious PAR files in Tecnomatix Plant Si...

Jul 11, 2023
CVE-2023-30647
7.8

This CVE describes a heap out-of-bounds write vulnerability in Samsung's RILD (Radio Interface Layer Daemon) component that handles USIM phonebook cap...

Jul 6, 2023
CVE-2023-30649
7.8

This vulnerability allows attackers to execute arbitrary code on Samsung mobile devices by exploiting a heap out-of-bounds write in the RILD component...

Jul 6, 2023
CVE-2023-30645
7.8

This vulnerability allows attackers to write beyond heap memory boundaries in Samsung's RILD (Radio Interface Layer Daemon) component, potentially lea...

Jul 6, 2023
CVE-2023-35001
7.8

This vulnerability in the Linux kernel's nftables subsystem allows local users with CAP_NET_ADMIN capability to trigger out-of-bounds read/write opera...

Jul 5, 2023
CVE-2023-3090
7.8

This CVE describes a heap out-of-bounds write vulnerability in the Linux Kernel's ipvlan network driver that allows local attackers to escalate privil...

Jun 28, 2023
CVE-2023-32380
7.8

This vulnerability allows attackers to execute arbitrary code on affected macOS systems by tricking users into processing a malicious 3D model file. I...

Jun 23, 2023
CVE-2023-23516
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS Big S...

Jun 23, 2023
CVE-2023-36192
7.8

CVE-2023-36192 is a heap buffer overflow vulnerability in sngrep v1.6.0 that allows attackers to execute arbitrary code or cause denial of service by ...

Jun 23, 2023
CVE-2023-32276
7.8

A stack-based buffer overflow vulnerability in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0 allows attackers to execute arbitrary code or disclose infor...

Jun 19, 2023
CVE-2023-32538
7.8

A stack-based buffer overflow vulnerability in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0 allows attackers to execute arbitrary code or disclose infor...

Jun 19, 2023
CVE-2023-35788
7.8

This vulnerability allows attackers to perform out-of-bounds writes in the Linux kernel's flower classifier code via specially crafted GENEVE packets....

Jun 16, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,123 CVEs classified as CWE-787, with 750 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free