CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,123
Total CVEs
750
Critical
2,160
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
96
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 246
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,123)

CVE-2023-29160
7.8

A stack-based buffer overflow vulnerability in FRENIC RHC Loader v1.1.0.3 allows attackers to execute arbitrary code or disclose sensitive information...

Jun 13, 2023
CVE-2023-33551
7.8

This CVE describes a heap buffer overflow vulnerability in erofs-utils v1.6 that allows remote attackers to execute arbitrary code by providing a mali...

Jun 1, 2023
CVE-2023-31722
7.8

CVE-2023-31722 is a heap buffer overflow vulnerability in NASM (Netwide Assembler) version 2.16.02rc1 that allows attackers to execute arbitrary code ...

May 17, 2023
CVE-2023-2124
7.8

A local privilege escalation vulnerability exists in the Linux kernel's XFS filesystem when restoring from a dirty log journal after failure. This all...

May 15, 2023
CVE-2023-25009
7.8

This vulnerability allows remote code execution through malicious USD files in Autodesk software. An attacker can craft a USD file that triggers an ou...

May 12, 2023
CVE-2023-29282
7.8

Adobe Substance 3D Painter versions 8.3.0 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary cod...

May 11, 2023
CVE-2023-31907
7.8

CVE-2023-31907 is a heap buffer overflow vulnerability in Jerryscript 3.0.0's scanner_literal_is_created function that could allow attackers to execut...

May 10, 2023
CVE-2023-31910
7.8

CVE-2023-31910 is a heap buffer overflow vulnerability in Jerryscript's parser component that could allow arbitrary code execution. This affects syste...

May 10, 2023
CVE-2023-27385
7.8

A heap-based buffer overflow vulnerability in CX-Drive software allows attackers to execute arbitrary code or disclose information by tricking users i...

May 10, 2023
CVE-2023-29462
7.8

This is a heap buffer overflow vulnerability in Rockwell Automation's Arena Simulation software that allows arbitrary code execution. An attacker coul...

May 9, 2023
CVE-2023-31982
7.8

CVE-2023-31982 is a heap buffer overflow vulnerability in sngrep v1.6.0 that allows attackers to execute arbitrary code or cause denial of service by ...

May 9, 2023
CVE-2023-27936
7.8

This CVE describes an out-of-bounds write vulnerability in Apple operating systems that allows an application to write to kernel memory or cause syste...

May 8, 2023
CVE-2023-31284
7.8

CVE-2023-31284 is a stack buffer overflow vulnerability in illumos's /dev/net device driver that allows local attackers to execute arbitrary code with...

May 4, 2023
CVE-2023-31436
7.8

This vulnerability in the Linux kernel's QFQ scheduler allows an out-of-bounds write due to improper bounds checking. Attackers with local access can ...

Apr 28, 2023
CVE-2023-23579
7.8

This vulnerability in Datakit CrossCadWare_x64.dll allows remote code execution through an out-of-bounds write when parsing malicious SLDPRT files. At...

Apr 20, 2023
CVE-2023-21100
7.8

This CVE describes a heap buffer overflow vulnerability in Android's inflate.c library that allows local privilege escalation without user interaction...

Apr 19, 2023
CVE-2023-27909
7.8

An out-of-bounds write vulnerability in Autodesk FBX SDK versions 2020 and earlier allows attackers to execute arbitrary code or disclose information ...

Apr 17, 2023
CVE-2023-27911
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious FBX files. It affects systems using Autodesk FB...

Apr 17, 2023
CVE-2023-22669
7.8

This is a heap-based buffer overflow vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing malicious DW...

Apr 15, 2023
CVE-2023-27914
7.8

A stack buffer overflow vulnerability in Autodesk AutoCAD 2023 allows attackers to execute arbitrary code or read sensitive data by tricking users int...

Apr 14, 2023
CVE-2023-29067
7.8

A memory corruption vulnerability in Autodesk AutoCAD 2023 allows attackers to execute arbitrary code by tricking users into opening malicious X_B fil...

Apr 14, 2023
CVE-2023-29491
7.8

This vulnerability in ncurses allows local users to trigger memory corruption by providing malformed terminfo database files. It affects setuid applic...

Apr 14, 2023
CVE-2023-26415
7.8

Adobe Substance 3D Designer versions 12.4.0 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code w...

Apr 13, 2023
CVE-2023-21582
7.8

CVE-2023-21582 is an out-of-bounds write vulnerability in Adobe Digital Editions that could allow arbitrary code execution when a user opens a malicio...

Apr 12, 2023
CVE-2022-42858
7.8

CVE-2022-42858 is a memory corruption vulnerability in macOS that allows malicious applications to execute arbitrary code with kernel privileges. This...

Apr 10, 2023
CVE-2023-0182
7.8

This vulnerability in NVIDIA GPU Display Driver for Windows allows attackers to write data beyond allocated memory boundaries in the kernel mode layer...

Apr 1, 2023
CVE-2022-44370
7.8

CVE-2022-44370 is a heap buffer overflow vulnerability in NASM (Netwide Assembler) v2.16 that allows attackers to execute arbitrary code or cause deni...

Mar 29, 2023
CVE-2022-43618
7.8

CVE-2022-43618 is a heap-based buffer overflow vulnerability in CorelDRAW Graphics Suite that allows remote code execution when processing malicious P...

Mar 29, 2023
CVE-2022-37371
7.8

CVE-2022-37371 is a buffer overflow vulnerability in PDF-XChange Editor that allows remote code execution when a user opens a malicious PDF file. Atta...

Mar 29, 2023
CVE-2022-37362
7.8

CVE-2022-37362 is a buffer overflow vulnerability in PDF-XChange Editor's PNG file parser that allows remote code execution. Attackers can exploit thi...

Mar 29, 2023
CVE-2022-37364
7.8

CVE-2022-37364 is a buffer overflow vulnerability in PDF-XChange Editor's EMF file parser that allows remote code execution. Attackers can exploit thi...

Mar 29, 2023
CVE-2022-37369
7.8

CVE-2022-37369 is a buffer overflow vulnerability in PDF-XChange Editor's PDF parsing functionality. It allows remote attackers to execute arbitrary c...

Mar 29, 2023
CVE-2022-37354
7.8

CVE-2022-37354 is a buffer overflow vulnerability in PDF-XChange Editor's J2K file parser that allows remote code execution. Attackers can exploit thi...

Mar 29, 2023
CVE-2022-37356
7.8

CVE-2022-37356 is a buffer overflow vulnerability in PDF-XChange Editor's JPG file parser that allows remote code execution when a user opens a malici...

Mar 29, 2023
CVE-2022-37358
7.8

CVE-2022-37358 is a buffer overflow vulnerability in PDF-XChange Editor's JPG file parser that allows remote code execution. Attackers can exploit thi...

Mar 29, 2023
CVE-2022-28646
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious IFC files in Bentley MicroStation CONNEC...

Mar 29, 2023
CVE-2022-28314
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC files. Attacke...

Mar 29, 2023
CVE-2022-28316
7.8

CVE-2022-28316 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC file...

Mar 29, 2023
CVE-2022-28318
7.8

CVE-2022-28318 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC file...

Mar 29, 2023
CVE-2022-28642
7.8

CVE-2022-28642 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious DGN file...

Mar 29, 2023
CVE-2022-28644
7.8

CVE-2022-28644 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious DGN file...

Mar 29, 2023
CVE-2022-28301
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC files. Attacke...

Mar 29, 2023
CVE-2023-25905
7.8

CVE-2023-25905 is an out-of-bounds write vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a malicious file...

Mar 28, 2023
CVE-2022-1229
7.8

CVE-2022-1229 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC files...

Mar 28, 2023
CVE-2023-21040
7.8

This CVE describes a local privilege escalation vulnerability in Android's Bluetooth stack. An attacker can exploit a logic error in the bluetooth_ccc...

Mar 24, 2023
CVE-2023-20985
7.8

This vulnerability in Android's Bluetooth stack allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated privi...

Mar 24, 2023
CVE-2023-20966
7.8

This CVE describes a heap buffer overflow vulnerability in Android's inflate.c library that allows local privilege escalation without user interaction...

Mar 24, 2023
CVE-2023-20931
7.8

This CVE describes a heap buffer overflow vulnerability in Android's AVDT (Audio/Video Distribution Transport) protocol stack. An attacker could explo...

Mar 24, 2023
CVE-2023-25861
7.8

CVE-2023-25861 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious fi...

Mar 22, 2023
CVE-2023-27400
7.8

This vulnerability allows remote code execution via specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bounds...

Mar 14, 2023

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,123 CVEs classified as CWE-787, with 750 rated critical and 2,160 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free