CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,224)
This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...
May 26, 2022CVE-2022-26736 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...
May 26, 2022CVE-2022-22672 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...
May 26, 2022CVE-2022-22675 is an out-of-bounds write vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel pri...
May 26, 2022CVE-2022-30788 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_mft_rec_alloc function. Attackers can exploit this by mounting a specia...
May 26, 2022CVE-2022-30786 is a heap-based buffer overflow vulnerability in NTFS-3G's ntfs_names_full_collate function that allows attackers to execute arbitrary ...
May 26, 2022CVE-2022-27653 is an out-of-bounds write vulnerability in Simcenter Femap that allows remote code execution when parsing malicious .NEU files. Attacke...
May 20, 2022CVE-2021-42704 is an out-of-bounds write vulnerability in Inkscape 0.91 that could allow remote code execution when processing malicious files. This a...
May 18, 2022Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...
May 13, 2022CVE-2022-28827 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...
May 13, 2022CVE-2022-28829 is an out-of-bounds write vulnerability in Adobe Framemaker that could allow arbitrary code execution when a user opens a malicious fil...
May 13, 2022Adobe Framemaker has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects users ...
May 13, 2022Adobe Character Animator has an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malicious SVG file. This af...
May 12, 2022CVE-2021-26386 is a memory corruption vulnerability in AMD's Stage 2 Bootloader that could allow a malicious or compromised UApp or ABL to execute arb...
May 12, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow an attacker to execute arbitrary code on a victim'...
May 11, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...
May 11, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...
May 11, 2022This CVE describes a stack overflow vulnerability in the MmtAtePrase function of several TP-Link, Mercury, and Fast router models. Local users can exp...
May 10, 2022CVE-2022-30524 is an invalid memory access vulnerability in Xpdf's text extraction functionality that allows remote attackers to cause denial of servi...
May 9, 2022Adobe Photoshop versions 22.5.6 and earlier, and 23.2.2 and earlier, contain an out-of-bounds write vulnerability in SVG file parsing. When exploited,...
May 6, 2022Adobe Photoshop versions 22.5.6 and earlier and 23.2.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute ...
May 6, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code on affected systems. T...
May 6, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code on affected systems. U...
May 6, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow attackers to execute arbitrary code when a user opens a ma...
May 6, 2022This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a malicious U3D...
May 6, 2022CVE-2022-27470 is an arbitrary memory write vulnerability in SDL_ttf library versions 2.0.18 and below. Attackers can exploit this by providing a mali...
May 4, 2022CVE-2022-20099 is an out-of-bounds write vulnerability in the aee daemon on MediaTek devices, allowing local privilege escalation to System level with...
May 3, 2022A stack-based buffer overflow vulnerability in cifs-utils versions through 6.14 allows local attackers to escalate privileges to root when parsing the...
Apr 27, 2022This vulnerability in Autodesk AutoCAD 2022 allows an attacker to execute arbitrary code by tricking a user into opening a maliciously crafted JT file...
Apr 19, 2022This vulnerability allows an attacker to execute arbitrary code by tricking a user into opening a malicious TGA image file in Autodesk Design Review. ...
Apr 18, 2022A buffer overflow vulnerability in Autodesk AutoCAD allows attackers to execute arbitrary code by tricking users into opening malicious TIF or PICT fi...
Apr 18, 2022This vulnerability in 7-Zip allows attackers to execute arbitrary commands with elevated privileges when a malicious .7z file is dragged to the Help>C...
Apr 15, 2022This vulnerability allows remote code execution through specially crafted .NEU files in Simcenter Femap. Attackers can exploit an out-of-bounds write ...
Apr 12, 2022A memory corruption vulnerability in Autodesk AutoCAD and Navisworks allows attackers to execute arbitrary code by tricking users into opening malicio...
Apr 11, 2022This vulnerability is a heap buffer overflow in radare2's NE file format parser that allows writing beyond allocated memory boundaries. Attackers coul...
Apr 6, 2022This vulnerability allows an attacker to write data beyond allocated memory bounds in Qualcomm Snapdragon chipsets due to improper validation of timer...
Apr 1, 2022This vulnerability in Android's Keymaster component allows local attackers to write data beyond allocated memory boundaries due to missing bounds chec...
Mar 30, 2022CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux kernel's watch_queue subsystem that allows a local attacker to overwrite kernel mem...
Mar 25, 2022CVE-2021-28278 is a heap-based buffer overflow vulnerability in jhead image metadata tool versions 3.04 and 3.05. Attackers can exploit this by crafti...
Mar 23, 2022CVE-2022-27666 is a heap buffer overflow vulnerability in the Linux kernel's IPsec ESP transformation code. It allows local attackers with standard us...
Mar 23, 2022CVE-2022-24091 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious f...
Mar 18, 2022This vulnerability allows an attacker to cause heap corruption by tricking a user into processing a maliciously crafted image. It affects Apple device...
Mar 18, 2022CVE-2022-22584 is a memory corruption vulnerability in Apple operating systems that allows arbitrary code execution when processing malicious files. A...
Mar 18, 2022This is a memory corruption vulnerability in Apple's iOS, iPadOS, and watchOS that allows an application to execute arbitrary code with kernel privile...
Mar 18, 2022This vulnerability allows arbitrary code execution via malicious font files due to an out-of-bounds write in Apple's font processing. It affects macOS...
Mar 18, 2022A stack overflow vulnerability in the upnpd service of affected Netgear devices allows unauthenticated attackers to execute arbitrary code remotely. T...
Mar 18, 2022This CVE describes a local privilege escalation vulnerability in the Mali GPU kernel driver for Android. An attacker could exploit a logic error in me...
Mar 16, 2022CVE-2022-24575 is a stack-based buffer overflow vulnerability in GPAC's MP4Box tool that allows attackers to execute arbitrary code or cause denial of...
Mar 14, 2022CVE-2022-26967 is a heap-based buffer overflow vulnerability in GPAC's gf_base64_encode function that can be triggered via MP4Box. This allows attacke...
Mar 12, 2022CVE-2022-21124 is an out-of-bounds write vulnerability in Omron CX-Programmer software that allows attackers to execute arbitrary code or disclose inf...
Mar 10, 2022About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,224 CVEs classified as CWE-787, with 805 rated critical and 2,206 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free