CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,246
Total CVEs
808
Critical
2,225
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 389
2 Adobe 271
3 Linux 229
4 Apple 209
5 Tenda 189
6 Debian 187
7 Fedoraproject 130
8 Microsoft 79
9 Mozilla 78
10 Samsung 77

All Out-of-bounds Write CVEs (3,246)

CVE-2021-46482
7.8

CVE-2021-46482 is a heap buffer overflow vulnerability in Jsish v3.5.0's NumberConstructor function that allows attackers to execute arbitrary code or...

Jan 25, 2022
CVE-2022-23850
7.8

CVE-2022-23850 is a stack-based buffer overflow vulnerability in epub2txt's xhtml_translate_entity function that allows remote code execution via a sp...

Jan 23, 2022
CVE-2022-22893
7.8

CVE-2022-22893 is a stack overflow vulnerability in Jerryscript 3.0.0's VM component that allows attackers to execute arbitrary code or cause denial o...

Jan 21, 2022
CVE-2022-22895
7.8

CVE-2022-22895 is a heap buffer overflow vulnerability in Jerryscript 3.0.0's string-to-number conversion function. This allows attackers to write bey...

Jan 21, 2022
CVE-2022-22888
7.8

CVE-2022-22888 is a stack overflow vulnerability in Jerryscript 3.0.0's ecma_op_object_find_own function that allows attackers to execute arbitrary co...

Jan 20, 2022
CVE-2021-46324
7.8

Espruino 2v11.251 contains a stack buffer overflow vulnerability in the jsvNewFromString function in src/jsvar.c. This allows attackers to execute arb...

Jan 20, 2022
CVE-2021-46326
7.8

CVE-2021-46326 is a heap buffer overflow vulnerability in Moddable SDK v11.5.0 that occurs in the __asan_memcpy component. This vulnerability could al...

Jan 20, 2022
CVE-2021-46328
7.8

CVE-2021-46328 is a heap buffer overflow vulnerability in Moddable SDK v11.5.0 that occurs via the __libc_start_main component. This vulnerability cou...

Jan 20, 2022
CVE-2021-46332
7.8

CVE-2021-46332 is a heap buffer overflow vulnerability in Moddable SDK's DataView implementation that allows attackers to read beyond allocated memory...

Jan 20, 2022
CVE-2021-46334
7.8

CVE-2021-46334 is a stack buffer overflow vulnerability in Moddable SDK v11.5.0 that occurs via the __interceptor_strcat component. This vulnerability...

Jan 20, 2022
CVE-2021-45417
7.8

CVE-2021-45417 is a heap-based buffer overflow vulnerability in AIDE (Advanced Intrusion Detection Environment) that allows local users to escalate pr...

Jan 20, 2022
CVE-2022-23095
7.8

CVE-2022-23095 is a memory corruption vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing malicious J...

Jan 15, 2022
CVE-2021-45068
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...

Jan 14, 2022
CVE-2021-44743
7.8

Adobe Bridge versions 11.1.2 and earlier, and 12.0 and earlier, contain an out-of-bounds write vulnerability that could allow an attacker to execute a...

Jan 14, 2022
CVE-2021-44707
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that could allow arbitrary code execution when a user opens a malic...

Jan 14, 2022
CVE-2021-39632
7.8

This CVE describes a local privilege escalation vulnerability in Android's inotify subsystem where an incorrect bounds check allows out-of-bounds writ...

Jan 14, 2022
CVE-2021-34921
7.8

CVE-2021-34921 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit this by tr...

Jan 13, 2022
CVE-2021-34923
7.8

CVE-2021-34923 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit this by tr...

Jan 13, 2022
CVE-2021-34929
7.8

CVE-2021-34929 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit it by tric...

Jan 13, 2022
CVE-2021-34935
7.8

CVE-2021-34935 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit this by tr...

Jan 13, 2022
CVE-2021-34897
7.8

CVE-2021-34897 is a buffer overflow vulnerability in Bentley View's DGN file parser that allows remote code execution. Attackers can exploit this by t...

Jan 13, 2022
CVE-2021-34899
7.8

CVE-2021-34899 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit it by tric...

Jan 13, 2022
CVE-2021-34903
7.8

CVE-2021-34903 is a buffer overflow vulnerability in Bentley View's BMP file parser that allows remote code execution. Attackers can exploit it by tri...

Jan 13, 2022
CVE-2021-34915
7.8

This is a buffer overflow vulnerability in Bentley View's J2K file parser that allows remote code execution when a user opens a malicious J2K file or ...

Jan 13, 2022
CVE-2021-34876
7.8

CVE-2021-34876 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit it by tric...

Jan 13, 2022
CVE-2021-34878
7.8

CVE-2021-34878 is a buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit it by tric...

Jan 13, 2022
CVE-2021-45053
7.8

Adobe InCopy versions 16.4 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a victim's...

Jan 13, 2022
CVE-2021-45057
7.8

Adobe InDesign versions 16.4 and earlier contain an out-of-bounds write vulnerability in JPEG2000 file parsing. Attackers can exploit this by tricking...

Jan 13, 2022
CVE-2021-36412
7.8

A heap-based buffer overflow vulnerability in GPAC's MP4Box tool allows attackers to execute arbitrary code or cause denial of service by processing a...

Jan 10, 2022
CVE-2021-43579
7.8

CVE-2021-43579 is a stack-based buffer overflow vulnerability in HTMLDOC's BMP image processing function that allows remote code execution when proces...

Jan 10, 2022
CVE-2021-22045
7.8

This CVE describes a heap-overflow vulnerability in VMware's CD-ROM device emulation that could allow a malicious actor with access to a virtual machi...

Jan 4, 2022
CVE-2021-45926
7.8

CVE-2021-45926 is a stack-based buffer overflow vulnerability in MDB Tools (mdbtools) that allows attackers to execute arbitrary code or cause denial ...

Jan 1, 2022
CVE-2021-45907
7.8

CVE-2021-45907 is a stack-based buffer overflow vulnerability in gif2apng 1.9 that occurs during GIF to APNG conversion. While attackers have limited ...

Dec 28, 2021
CVE-2021-45909
7.8

CVE-2021-45909 is a heap-based buffer overflow vulnerability in gif2apng's DecodeLZW function that allows attackers to write arbitrary data beyond buf...

Dec 28, 2021
CVE-2021-45911
7.8

CVE-2021-45911 is a heap-based buffer overflow vulnerability in gif2apng 1.9 that allows attackers to write 2 bytes outside buffer boundaries. This af...

Dec 28, 2021
CVE-2021-44181
7.8

Adobe Dimension versions 3.4.3 and earlier contain an out-of-bounds write vulnerability in GIF file processing. Attackers can exploit this by tricking...

Dec 20, 2021
CVE-2021-38419
7.8

This vulnerability in Fuji Electric V-Server Lite and Tellus Lite V-Simulator allows attackers to write data beyond allocated memory boundaries, poten...

Dec 20, 2021
CVE-2021-45078
7.8

This vulnerability in GNU Binutils allows attackers to trigger a heap-based buffer overflow via the stab_xcoff_builtin_type function in stabs.c. It ca...

Dec 15, 2021
CVE-2021-1044
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the identity support component. Attackers ca...

Dec 15, 2021
CVE-2021-0675
7.8

CVE-2021-0675 is an out-of-bounds write vulnerability in the ALAC (Apple Lossless Audio Codec) decoder used in MediaTek chipsets. This allows local at...

Dec 15, 2021
CVE-2021-43247
7.8

This vulnerability in the Windows TCP/IP driver allows an attacker to execute arbitrary code with elevated SYSTEM privileges. It affects Windows syste...

Dec 15, 2021
CVE-2021-44434
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. An attacker could execut...

Dec 14, 2021
CVE-2021-44437
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44441
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44443
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44449
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK libraries. Attackers can exploit a...

Dec 14, 2021
CVE-2021-44001
7.8

This vulnerability allows remote code execution through specially crafted PDF files in Siemens JT2Go and Teamcenter Visualization software. Attackers ...

Dec 14, 2021
CVE-2021-44005
7.8

This vulnerability allows remote code execution through specially crafted TIFF files in Siemens JT2Go and Teamcenter Visualization software. Attackers...

Dec 14, 2021
CVE-2021-44013
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT2Go and Teamcenter Visualization software. Attackers c...

Dec 14, 2021
CVE-2021-42024
7.8

CVE-2021-42024 is an out-of-bounds write vulnerability in Simcenter STAR-CCM+ Viewer that allows remote code execution when parsing malicious scene fi...

Dec 14, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,246 CVEs classified as CWE-787, with 808 rated critical and 2,225 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free