CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,136
Total CVEs
760
Critical
2,163
High
8.2
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 254
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 178
7 Fedoraproject 125
8 Samsung 77
9 Siemens 75
10 Microsoft 71

All Out-of-bounds Write CVEs (3,136)

CVE-2022-28318
7.8

CVE-2022-28318 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC file...

Mar 29, 2023
CVE-2022-28642
7.8

CVE-2022-28642 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious DGN file...

Mar 29, 2023
CVE-2022-28644
7.8

CVE-2022-28644 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious DGN file...

Mar 29, 2023
CVE-2022-28301
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC files. Attacke...

Mar 29, 2023
CVE-2023-25905
7.8

CVE-2023-25905 is an out-of-bounds write vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a malicious file...

Mar 28, 2023
CVE-2022-1229
7.8

CVE-2022-1229 is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious IFC files...

Mar 28, 2023
CVE-2023-21040
7.8

This CVE describes a local privilege escalation vulnerability in Android's Bluetooth stack. An attacker can exploit a logic error in the bluetooth_ccc...

Mar 24, 2023
CVE-2023-20985
7.8

This vulnerability in Android's Bluetooth stack allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated privi...

Mar 24, 2023
CVE-2023-20966
7.8

This CVE describes a heap buffer overflow vulnerability in Android's inflate.c library that allows local privilege escalation without user interaction...

Mar 24, 2023
CVE-2023-20931
7.8

This CVE describes a heap buffer overflow vulnerability in Android's AVDT (Audio/Video Distribution Transport) protocol stack. An attacker could explo...

Mar 24, 2023
CVE-2023-25861
7.8

CVE-2023-25861 is an out-of-bounds write vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious fi...

Mar 22, 2023
CVE-2023-27400
7.8

This vulnerability allows remote code execution via specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bounds...

Mar 14, 2023
CVE-2023-27398
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Mar 14, 2023
CVE-2023-27117
7.8

CVE-2023-27117 is a heap overflow vulnerability in WebAssembly Binary Toolkit (wabt) version 1.0.29 that allows attackers to execute arbitrary code or...

Mar 10, 2023
CVE-2023-0622
7.8

Cscape Envision RV version 4.60 has an out-of-bounds write vulnerability when parsing HMI project files. This allows attackers to execute arbitrary co...

Mar 9, 2023
CVE-2023-27566
7.8

CVE-2023-27566 is an out-of-bounds write vulnerability in Live2D Cubism Editor's Cubism Core component that allows attackers to execute arbitrary code...

Mar 3, 2023
CVE-2023-25221
7.8

This vulnerability is a heap buffer overflow in libde265's motion.cc component, allowing attackers to execute arbitrary code or cause denial of servic...

Mar 1, 2023
CVE-2023-22230
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Bridge that could allow an attacker to execute arbitrary code on a victim's system. T...

Feb 17, 2023
CVE-2023-22237
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious...

Feb 17, 2023
CVE-2023-21576
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow an attacker to execute arbitrary code on a victim's system...

Feb 17, 2023
CVE-2023-21619
7.8

CVE-2023-21619 is an out-of-bounds write vulnerability in Adobe FrameMaker that could allow arbitrary code execution when a user opens a malicious fil...

Feb 17, 2023
CVE-2022-40080
7.8

This CVE describes a stack overflow vulnerability in the BIOS firmware of Acer Aspire E5-475G laptops. It allows local attackers to execute arbitrary ...

Feb 16, 2023
CVE-2023-24985
7.8

This vulnerability allows remote code execution through a buffer overflow when parsing malicious SPP files in Tecnomatix Plant Simulation. Attackers c...

Feb 14, 2023
CVE-2023-24987
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Feb 14, 2023
CVE-2023-24989
7.8

This vulnerability in Tecnomatix Plant Simulation allows remote code execution via a specially crafted SPP file, enabling an attacker to run arbitrary...

Feb 14, 2023
CVE-2023-24991
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Feb 14, 2023
CVE-2023-24993
7.8

This vulnerability allows remote code execution via specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can execute arbitrary code i...

Feb 14, 2023
CVE-2023-24995
7.8

This vulnerability allows remote code execution via specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bounds...

Feb 14, 2023
CVE-2023-24979
7.8

This vulnerability in Tecnomatix Plant Simulation allows remote code execution via a specially crafted SPP file, enabling an attacker to run arbitrary...

Feb 14, 2023
CVE-2023-24981
7.8

This vulnerability allows remote code execution through specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can exploit an out-of-bo...

Feb 14, 2023
CVE-2023-24983
7.8

This vulnerability allows remote code execution via specially crafted SPP files in Tecnomatix Plant Simulation. Attackers can execute arbitrary code i...

Feb 14, 2023
CVE-2023-24560
7.8

This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting an out-of-bounds write when parsing malicious PAR files. Use...

Feb 14, 2023
CVE-2022-45493
7.8

This is a buffer overflow vulnerability in the json_parse_key function of the sheredom json.h library. It allows attackers to execute arbitrary code a...

Feb 3, 2023
CVE-2022-45491
7.8

This is a buffer overflow vulnerability in the json_parse_value function of the sheredom json.h library. It allows attackers to execute arbitrary code...

Feb 3, 2023
CVE-2023-0124
7.8

Delta Electronics DOPSoft versions 4.00.16.22 and prior contain an out-of-bounds write vulnerability that allows remote code execution when processing...

Feb 3, 2023
CVE-2022-45188
7.8

CVE-2022-45188 is a heap-based buffer overflow vulnerability in Netatalk's afp_getappl function that allows remote code execution via a malicious .app...

Nov 12, 2022
CVE-2022-34251
7.8

Adobe InCopy versions 17.2 and earlier (macOS/Windows) and 16.4.1 and earlier (macOS/Windows) contain an out-of-bounds write vulnerability that could ...

Jul 15, 2022
CVE-2022-34247
7.8

Adobe InDesign versions 17.2.1 and earlier (and 16.4.1 and earlier) contain an out-of-bounds write vulnerability that could allow attackers to execute...

Jul 15, 2022
CVE-2022-34217
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a maliciou...

Jul 15, 2022
CVE-2022-22049
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges on affected Windows systems by exploiting a flaw ...

Jul 12, 2022
CVE-2022-33108
7.8

CVE-2022-33108 is a stack overflow vulnerability in XPDF v4.04's Object::Copy class that allows attackers to execute arbitrary code by crafting malici...

Jun 28, 2022
CVE-2022-2210
7.8

CVE-2022-2210 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 27, 2022
CVE-2022-33032
7.8

LibreDWG v0.12.4.4608 contains a heap buffer overflow vulnerability in the decode_preR13_section_hdr function. This allows attackers to execute arbitr...

Jun 23, 2022
CVE-2022-33034
7.8

CVE-2022-33034 is a stack overflow vulnerability in LibreDWG's decode_r2007.c file that allows attackers to execute arbitrary code or cause denial of ...

Jun 23, 2022
CVE-2022-27870
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious TGA image files in AutoCAD 2023. The buffer ove...

Jun 21, 2022
CVE-2022-2129
7.8

CVE-2022-2129 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 19, 2022
CVE-2022-30652
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious file. ...

Jun 16, 2022
CVE-2022-30656
7.8

CVE-2022-30656 is an out-of-bounds write vulnerability in Adobe InCopy that allows arbitrary code execution when a user opens a malicious file. This a...

Jun 16, 2022
CVE-2022-30664
7.8

CVE-2022-30664 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. This ...

Jun 16, 2022
CVE-2022-30663
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system ...

Jun 16, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,136 CVEs classified as CWE-787, with 760 rated critical and 2,163 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free