CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,224
Total CVEs
805
Critical
2,206
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 268
3 Linux 229
4 Apple 209
5 Tenda 189
6 Debian 185
7 Fedoraproject 130
8 Mozilla 78
9 Samsung 77
10 Microsoft 76

All Out-of-bounds Write CVEs (3,224)

CVE-2022-26714
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

May 26, 2022
CVE-2022-26736
7.8

CVE-2022-26736 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-22672
7.8

CVE-2022-22672 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...

May 26, 2022
CVE-2022-22675
7.8

CVE-2022-22675 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...

May 26, 2022
CVE-2022-30788
7.8

CVE-2022-30788 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_mft_rec_alloc function. Attackers can exploit this by mounting a specia...

May 26, 2022
CVE-2022-30786
7.8

CVE-2022-30786 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_names_full_collate function that allows attackers to execute arbitrary ...

May 26, 2022
CVE-2022-27653
7.8

CVE-2022-27653 is an out-of-bounds write vulnerability in Simcenter Femap that allows remote code execution when parsing malicious .NEU files. Attacke...

May 20, 2022
CVE-2021-42704
7.8

CVE-2021-42704 is an out-of-bounds write vulnerability in Inkscape 0.91 that could allow remote code execution when processing malicious files. This a...

May 18, 2022
CVE-2022-28825
7.8

Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...

May 13, 2022
CVE-2022-28827
7.8

CVE-2022-28827 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...

May 13, 2022
CVE-2022-28829
7.8

CVE-2022-28829 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...

May 13, 2022
CVE-2022-28821
7.8

Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...

May 13, 2022
CVE-2022-28819
7.8

Adobe Character Animator has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious SVG file. This af...

May 12, 2022
CVE-2021-26386
7.8

CVE-2021-26386 is a memory corruption vulnerability in AMD's Stage 2 Bootloader that could allow a malicious or compromised UApp or ABL to execute arb...

May 12, 2022
CVE-2022-28236
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow an attacker to execute arbitrary code on a victim'...

May 11, 2022
CVE-2022-27787
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...

May 11, 2022
CVE-2022-27793
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...

May 11, 2022
CVE-2022-26987
7.8

This CVE describes a stack overflow vulnerability in the MmtAtePrase function of several TP-Link, Mercury, and Fast router models. Local users can exp...

May 10, 2022
CVE-2022-30524
7.8

CVE-2022-30524 is an invalid memory access vulnerability in Xpdf's text extraction functionality that allows remote attackers to cause denial of servi...

May 9, 2022
CVE-2022-28270
7.8

Adobe Photoshop versions 22.5.6 and earlier, and 23.2.2 and earlier, contain an out-of-bounds write vulnerability in SVG file parsing. When exploited,...

May 6, 2022
CVE-2022-28272
7.8

Adobe Photoshop versions 22.5.6 and earlier and 23.2.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute ...

May 6, 2022
CVE-2022-28276
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code on affected systems. T...

May 6, 2022
CVE-2022-28278
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code on affected systems. U...

May 6, 2022
CVE-2022-23205
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code when a user opens a ma...

May 6, 2022
CVE-2022-24105
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a malicious U3D...

May 6, 2022
CVE-2022-27470
7.8

CVE-2022-27470 is an arbitrary memory write vulnerability in SDL_ttf library versions 2.0.18 and below. Attackers can exploit this by providing a mali...

May 4, 2022
CVE-2022-20099
7.8

CVE-2022-20099 is an out-of-bounds write vulnerability in the aee daemon on MediaTek devices, allowing local privilege escalation to System level with...

May 3, 2022
CVE-2022-27239
7.8

A stack-based buffer overflow vulnerability in cifs-utils versions through 6.14 allows local attackers to escalate privileges to root when parsing the...

Apr 27, 2022
CVE-2022-25788
7.8

This vulnerability in Autodesk AutoCAD 2022 allows an attacker to execute arbitrary code by tricking a user into opening a maliciously crafted JT file...

Apr 19, 2022
CVE-2022-27526
7.8

This vulnerability allows an attacker to execute arbitrary code by tricking a user into opening a malicious TGA image file in Autodesk Design Review. ...

Apr 18, 2022
CVE-2022-27530
7.8

A buffer overflow vulnerability in Autodesk AutoCAD allows attackers to execute arbitrary code by tricking users into opening malicious TIF or PICT fi...

Apr 18, 2022
CVE-2022-29072
7.8

This vulnerability in 7-Zip allows attackers to execute arbitrary commands with elevated privileges when a malicious .7z file is dragged to the Help>C...

Apr 15, 2022
CVE-2022-28663
7.8

This vulnerability allows remote code execution through specially crafted .NEU files in Simcenter Femap. Attackers can exploit an out-of-bounds write ...

Apr 12, 2022
CVE-2022-25791
7.8

A memory corruption vulnerability in Autodesk AutoCAD and Navisworks allows attackers to execute arbitrary code by tricking users into opening malicio...

Apr 11, 2022
CVE-2022-1238
7.8

This vulnerability is a heap buffer overflow in radare2's NE file format parser that allows writing beyond allocated memory boundaries. Attackers coul...

Apr 6, 2022
CVE-2021-35103
7.8

This vulnerability allows an attacker to write data beyond allocated memory bounds in Qualcomm Snapdragon chipsets due to improper validation of timer...

Apr 1, 2022
CVE-2021-39741
7.8

This vulnerability in Android's Keymaster component allows local attackers to write data beyond allocated memory boundaries due to missing bounds chec...

Mar 30, 2022
CVE-2022-0995
7.8

CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux kernel's watch_queue subsystem that allows a local attacker to overwrite kernel mem...

Mar 25, 2022
CVE-2021-28278
7.8

CVE-2021-28278 is a heap-based buffer overflow vulnerability in jhead image metadata tool versions 3.04 and 3.05. Attackers can exploit this by crafti...

Mar 23, 2022
CVE-2022-27666
7.8

CVE-2022-27666 is a heap buffer overflow vulnerability in the Linux kernel's IPsec ESP transformation code. It allows local attackers with standard us...

Mar 23, 2022
CVE-2022-24091
7.8

CVE-2022-24091 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious f...

Mar 18, 2022
CVE-2022-22612
7.8

This vulnerability allows an attacker to cause heap corruption by tricking a user into processing a maliciously crafted image. It affects Apple device...

Mar 18, 2022
CVE-2022-22584
7.8

CVE-2022-22584 is a memory corruption vulnerability in Apple operating systems that allows arbitrary code execution when processing malicious files. A...

Mar 18, 2022
CVE-2022-22596
7.8

This is a memory corruption vulnerability in Apple's iOS, iPadOS, and watchOS that allows an application to execute arbitrary code with kernel privile...

Mar 18, 2022
CVE-2021-30771
7.8

This vulnerability allows arbitrary code execution via malicious font files due to an out-of-bounds write in Apple's font processing. It affects macOS...

Mar 18, 2022
CVE-2022-24655
7.8

A stack overflow vulnerability in the upnpd service of affected Netgear devices allows unauthenticated attackers to execute arbitrary code remotely. T...

Mar 18, 2022
CVE-2021-39793
7.8

This CVE describes a local privilege escalation vulnerability in the Mali GPU kernel driver for Android. An attacker could exploit a logic error in me...

Mar 16, 2022
CVE-2022-24575
7.8

CVE-2022-24575 is a stack-based buffer overflow vulnerability in GPAC's MP4Box tool that allows attackers to execute arbitrary code or cause denial of...

Mar 14, 2022
CVE-2022-26967
7.8

CVE-2022-26967 is a heap-based buffer overflow vulnerability in GPAC's gf_base64_encode function that can be triggered via MP4Box. This allows attacke...

Mar 12, 2022
CVE-2022-21124
7.8

CVE-2022-21124 is an out-of-bounds write vulnerability in Omron CX-Programmer software that allows attackers to execute arbitrary code or disclose inf...

Mar 10, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,224 CVEs classified as CWE-787, with 805 rated critical and 2,206 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free