CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,229
Total CVEs
805
Critical
2,211
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 388
2 Adobe 268
3 Linux 229
4 Apple 209
5 Tenda 189
6 Debian 185
7 Fedoraproject 130
8 Microsoft 79
9 Mozilla 78
10 Samsung 77

All Out-of-bounds Write CVEs (3,229)

CVE-2022-21124
7.8

CVE-2022-21124 is an out-of-bounds write vulnerability in Omron CX-Programmer software that allows attackers to execute arbitrary code or disclose inf...

Mar 10, 2022
CVE-2022-20047
7.8

CVE-2022-20047 is an out-of-bounds write vulnerability in MediaTek video decoder components that allows local privilege escalation without user intera...

Mar 10, 2022
CVE-2022-24453
7.8

CVE-2022-24453 is a remote code execution vulnerability in Microsoft's HEVC Video Extensions that allows attackers to execute arbitrary code by tricki...

Mar 9, 2022
CVE-2022-24457
7.8

CVE-2022-24457 is a remote code execution vulnerability in Microsoft's HEIF Image Extensions that allows attackers to execute arbitrary code by tricki...

Mar 9, 2022
CVE-2022-22007
7.8

CVE-2022-22007 is a remote code execution vulnerability in Microsoft's HEVC Video Extensions that allows attackers to execute arbitrary code by tricki...

Mar 9, 2022
CVE-2022-25465
7.8

Espruino 2v11 contains a stack buffer overflow vulnerability in the jsvGetNextSibling function in src/jsvar.c. This allows attackers to execute arbitr...

Mar 5, 2022
CVE-2021-3575
7.8

This vulnerability allows remote code execution via a heap-based buffer overflow in openjpeg when processing malicious JPEG 2000 (.j2k) files. Attacke...

Mar 4, 2022
CVE-2021-26259
7.8

CVE-2021-26259 is a heap buffer overflow vulnerability in htmldoc's render_table_row() function that could allow attackers to execute arbitrary code o...

Mar 3, 2022
CVE-2021-44335
7.8

CVE-2021-44335 is a heap buffer overflow vulnerability in the ok-file-formats library's PNG processing function. Attackers can exploit this by providi...

Mar 3, 2022
CVE-2021-44331
7.8

CVE-2021-44331 is a buffer overflow vulnerability in ARM's astcenc 3.2.0 Adaptive Scalable Texture Compression encoder. This vulnerability allows atta...

Feb 28, 2022
CVE-2021-44339
7.8

CVE-2021-44339 is a heap buffer overflow vulnerability in the ok-file-formats library's PNG processing function. Attackers can exploit this by craftin...

Feb 28, 2022
CVE-2021-26252
7.8

CVE-2021-26252 is a heap buffer overflow vulnerability in htmldoc's PDF processing component that could allow attackers to execute arbitrary code or c...

Feb 24, 2022
CVE-2021-46162
7.8

This vulnerability in Simcenter Femap allows remote code execution through specially crafted NEU files. An attacker could execute arbitrary code with ...

Feb 22, 2022
CVE-2022-24056
7.8

CVE-2022-24056 is a buffer overflow vulnerability in Sante DICOM Viewer Pro that allows remote code execution when a user opens a malicious J2K image ...

Feb 18, 2022
CVE-2022-24058
7.8

CVE-2022-24058 is a buffer overflow vulnerability in Sante DICOM Viewer Pro that allows remote code execution when a user opens a malicious J2K image ...

Feb 18, 2022
CVE-2022-24064
7.8

CVE-2022-24064 is a buffer overflow vulnerability in Sante DICOM Viewer Pro that allows remote code execution when parsing malicious J2K image files. ...

Feb 18, 2022
CVE-2021-46652
7.8

CVE-2021-46652 is a buffer overflow vulnerability in Bentley View's DGN file parser that allows remote code execution. Attackers can exploit it by tri...

Feb 18, 2022
CVE-2021-46635
7.8

CVE-2021-46635 is a buffer overflow vulnerability in Bentley MicroStation CONNECT's DGN file parser that allows remote code execution. Attackers can e...

Feb 18, 2022
CVE-2021-46640
7.8

This is a buffer overflow vulnerability in Bentley View's DGN file parser that allows remote code execution. Attackers can exploit it by tricking user...

Feb 18, 2022
CVE-2021-46645
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT's BMP image parser that allows remote code execution. Attackers can exploit it...

Feb 18, 2022
CVE-2021-46584
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious J2K image files in Bentley MicroStation ...

Feb 18, 2022
CVE-2021-46586
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious 3DS files. Attacke...

Feb 18, 2022
CVE-2021-46572
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution when users open malicious JT files. Attacker...

Feb 18, 2022
CVE-2021-46574
7.8

This is a remote code execution vulnerability in Bentley MicroStation CONNECT software. Attackers can execute arbitrary code by tricking users into op...

Feb 18, 2022
CVE-2021-46576
7.8

This is a remote code execution vulnerability in Bentley MicroStation CONNECT software that allows attackers to execute arbitrary code by tricking use...

Feb 18, 2022
CVE-2021-46568
7.8

This is a buffer overflow vulnerability in Bentley MicroStation CONNECT that allows remote code execution. Attackers can exploit it by tricking users ...

Feb 18, 2022
CVE-2021-46564
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JT files in Bentley MicroStation CONNECT...

Feb 18, 2022
CVE-2022-23200
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious...

Feb 16, 2022
CVE-2021-30322
7.8

This vulnerability allows an attacker to write data beyond the intended memory boundaries in Qualcomm Snapdragon chipsets due to improper validation o...

Feb 11, 2022
CVE-2022-20028
7.8

This CVE-2022-20028 is a Bluetooth stack vulnerability in MediaTek chipsets that allows local attackers to write beyond allocated memory boundaries, p...

Feb 9, 2022
CVE-2022-20040
7.8

CVE-2022-20040 is a stack-based buffer overflow vulnerability in MediaTek's power_hal_manager_service that allows local attackers to bypass permission...

Feb 9, 2022
CVE-2022-20026
7.8

This CVE describes a Bluetooth stack vulnerability in MediaTek chipsets that allows local privilege escalation without user interaction. An attacker w...

Feb 9, 2022
CVE-2021-0116
7.8

This vulnerability is an out-of-bounds write in Intel processor firmware that allows a privileged user to potentially escalate privileges via local ac...

Feb 9, 2022
CVE-2022-21926
7.8

CVE-2022-21926 is a remote code execution vulnerability in Microsoft's HEVC Video Extensions that allows attackers to execute arbitrary code by tricki...

Feb 9, 2022
CVE-2021-46151
7.8

This vulnerability allows remote code execution through specially crafted NEU files in Simcenter Femap. An attacker could execute arbitrary code with ...

Feb 9, 2022
CVE-2021-46159
7.8

This vulnerability allows remote code execution through specially crafted NEU files in Simcenter Femap engineering software. Attackers can exploit an ...

Feb 9, 2022
CVE-2021-46161
7.8

This vulnerability allows remote code execution through specially crafted NEU files in Simcenter Femap engineering software. Attackers can exploit an ...

Feb 9, 2022
CVE-2021-4034
7.8

CVE-2021-4034 (PwnKit) is a local privilege escalation vulnerability in polkit's pkexec utility that allows unprivileged local users to gain root priv...

Jan 28, 2022
CVE-2021-22807
7.8

This vulnerability allows arbitrary code execution when a malicious *.gd1 configuration file is loaded into the Eurotherm GUIcon tool. Attackers could...

Jan 28, 2022
CVE-2021-46522
7.8

CVE-2021-46522 is a heap buffer overflow vulnerability in Cesanta MJS JavaScript engine v2.20.0 that allows attackers to execute arbitrary code or cau...

Jan 27, 2022
CVE-2021-46524
7.8

CVE-2021-46524 is a heap buffer overflow vulnerability in Cesanta MJS v2.20.0 that allows attackers to execute arbitrary code or cause denial of servi...

Jan 27, 2022
CVE-2021-46518
7.8

CVE-2021-46518 is a heap buffer overflow vulnerability in Cesanta MJS JavaScript engine that allows attackers to execute arbitrary code or cause denia...

Jan 27, 2022
CVE-2021-46520
7.8

CVE-2021-46520 is a heap buffer overflow vulnerability in Cesanta MJS JavaScript engine v2.20.0 that allows attackers to execute arbitrary code or cau...

Jan 27, 2022
CVE-2021-46482
7.8

CVE-2021-46482 is a heap buffer overflow vulnerability in Jsish v3.5.0's NumberConstructor function that allows attackers to execute arbitrary code or...

Jan 25, 2022
CVE-2022-23850
7.8

CVE-2022-23850 is a stack-based buffer overflow vulnerability in epub2txt's xhtml_translate_entity function that allows remote code execution via a sp...

Jan 23, 2022
CVE-2022-22893
7.8

CVE-2022-22893 is a stack overflow vulnerability in Jerryscript 3.0.0's VM component that allows attackers to execute arbitrary code or cause denial o...

Jan 21, 2022
CVE-2022-22895
7.8

CVE-2022-22895 is a heap buffer overflow vulnerability in Jerryscript 3.0.0's string-to-number conversion function. This allows attackers to write bey...

Jan 21, 2022
CVE-2022-22888
7.8

CVE-2022-22888 is a stack overflow vulnerability in Jerryscript 3.0.0's ecma_op_object_find_own function that allows attackers to execute arbitrary co...

Jan 20, 2022
CVE-2021-46324
7.8

Espruino 2v11.251 contains a stack buffer overflow vulnerability in the jsvNewFromString function in src/jsvar.c. This allows attackers to execute arb...

Jan 20, 2022
CVE-2021-46326
7.8

CVE-2021-46326 is a heap buffer overflow vulnerability in Moddable SDK v11.5.0 that occurs in the __asan_memcpy component. This vulnerability could al...

Jan 20, 2022

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,229 CVEs classified as CWE-787, with 805 rated critical and 2,211 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free