CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,200
Total CVEs
798
Critical
2,189
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 268
3 Linux 229
4 Apple 202
5 Tenda 189
6 Debian 183
7 Fedoraproject 129
8 Samsung 77
9 Microsoft 76
10 Siemens 75

All Out-of-bounds Write CVEs (3,200)

CVE-2022-27870
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious TGA image files in AutoCAD 2023. The buffer ove...

Jun 21, 2022
CVE-2022-2129
7.8

CVE-2022-2129 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 19, 2022
CVE-2022-30652
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious file. ...

Jun 16, 2022
CVE-2022-30656
7.8

CVE-2022-30656 is an out-of-bounds write vulnerability in Adobe InCopy that allows arbitrary code execution when a user opens a malicious file. This a...

Jun 16, 2022
CVE-2022-30664
7.8

CVE-2022-30664 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. This ...

Jun 16, 2022
CVE-2022-30663
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system ...

Jun 16, 2022
CVE-2022-30659
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's system....

Jun 16, 2022
CVE-2022-30538
7.8

An out-of-bounds write vulnerability in the simulator module of Fuji Electric's V-SFT graphic editor versions prior to v6.1.6.0 allows attackers to ex...

Jun 16, 2022
CVE-2022-30649
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code on a victim's syst...

Jun 15, 2022
CVE-2022-28841
7.8

Adobe Bridge versions 12.0.1 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code with the privile...

Jun 15, 2022
CVE-2022-28843
7.8

CVE-2022-28843 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...

Jun 15, 2022
CVE-2022-28845
7.8

CVE-2022-28845 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...

Jun 15, 2022
CVE-2022-28847
7.8

CVE-2022-28847 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...

Jun 15, 2022
CVE-2021-43755
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious...

Jun 15, 2022
CVE-2022-28839
7.8

Adobe Bridge versions 12.0.1 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code with the privile...

Jun 15, 2022
CVE-2021-43754
7.8

Adobe Prelude versions 22.1.1 and earlier contain an out-of-bounds write vulnerability that allows attackers to execute arbitrary code by tricking use...

Jun 15, 2022
CVE-2021-39820
7.8

This vulnerability allows attackers to execute arbitrary code on affected Adobe InDesign installations by tricking users into opening malicious TIFF f...

Jun 15, 2022
CVE-2022-20147
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the NFC stack. Attackers can gain elevated p...

Jun 15, 2022
CVE-2022-26302
7.8

This CVE describes a heap-based buffer overflow vulnerability in the simulator module of Fuji Electric's V-SFT graphic editor. Attackers can exploit i...

Jun 14, 2022
CVE-2021-46816
7.8

Adobe Premiere Pro versions 15.4 and earlier contain a memory corruption vulnerability that allows arbitrary code execution when a user opens a malici...

Jun 13, 2022
CVE-2021-46818
7.8

Adobe Media Encoder versions 15.4 and earlier contain a memory corruption vulnerability that allows arbitrary code execution when a user opens a malic...

Jun 13, 2022
CVE-2022-2000
7.8

CVE-2022-2000 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

Jun 9, 2022
CVE-2022-31782
7.8

CVE-2022-31782 is a heap-based buffer overflow vulnerability in ftbench.c within FreeType demo programs. This vulnerability allows attackers to execut...

Jun 2, 2022
CVE-2022-27184
7.8

CVE-2022-27184 is an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected systems. This affects specific...

Jun 2, 2022
CVE-2022-1943
7.8

CVE-2022-1943 is an out-of-bounds memory write vulnerability in the Linux kernel's UDF file system driver. A local user can trigger this flaw through ...

Jun 2, 2022
CVE-2021-42195
7.8

CVE-2021-42195 is a heap buffer overflow vulnerability in swftools that allows attackers to execute arbitrary code by exploiting the handleEditText() ...

Jun 2, 2022
CVE-2021-42199
7.8

This CVE describes a heap buffer overflow vulnerability in swftools that allows remote code execution when processing malicious SWF files. Attackers c...

Jun 2, 2022
CVE-2021-42201
7.8

CVE-2021-42201 is a heap buffer overflow vulnerability in swftools that allows attackers to execute arbitrary code by exploiting the swf_GetD64() func...

Jun 2, 2022
CVE-2022-1897
7.8

CVE-2022-1897 is an out-of-bounds write vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code by tri...

May 27, 2022
CVE-2022-26751
7.8

This memory corruption vulnerability in Apple's image processing allows attackers to execute arbitrary code by tricking users into opening malicious i...

May 26, 2022
CVE-2022-26756
7.8

This is a macOS kernel vulnerability that allows an application to write data beyond allocated memory boundaries. Successful exploitation enables arbi...

May 26, 2022
CVE-2022-26761
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS Catal...

May 26, 2022
CVE-2022-26768
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

May 26, 2022
CVE-2022-26772
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS Monte...

May 26, 2022
CVE-2022-26739
7.8

CVE-2022-26739 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-26738
7.8

CVE-2022-26738 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-26714
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

May 26, 2022
CVE-2022-26736
7.8

CVE-2022-26736 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-22672
7.8

CVE-2022-22672 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...

May 26, 2022
CVE-2022-22675
7.8

CVE-2022-22675 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-30788
7.8

CVE-2022-30788 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_mft_rec_alloc function. Attackers can exploit this by mounting a specia...

May 26, 2022
CVE-2022-30786
7.8

CVE-2022-30786 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_names_full_collate function that allows attackers to execute arbitrary ...

May 26, 2022
CVE-2022-27653
7.8

CVE-2022-27653 is an out-of-bounds write vulnerability in Simcenter Femap that allows remote code execution when parsing malicious .NEU files. Attacke...

May 20, 2022
CVE-2021-42704
7.8

CVE-2021-42704 is an out-of-bounds write vulnerability in Inkscape 0.91 that could allow remote code execution when processing malicious files. This a...

May 18, 2022
CVE-2022-28825
7.8

Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...

May 13, 2022
CVE-2022-28827
7.8

CVE-2022-28827 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...

May 13, 2022
CVE-2022-28829
7.8

CVE-2022-28829 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...

May 13, 2022
CVE-2022-28821
7.8

Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...

May 13, 2022
CVE-2022-28819
7.8

Adobe Character Animator has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious SVG file. This af...

May 12, 2022
CVE-2021-26386
7.8

CVE-2021-26386 is a memory corruption vulnerability in AMD's Stage 2 Bootloader that could allow a malicious or compromised UApp or ABL to execute arb...

May 12, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,200 CVEs classified as CWE-787, with 798 rated critical and 2,189 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free