CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,280
Total CVEs
812
Critical
2,255
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 394
2 Adobe 271
3 Linux 231
4 Apple 223
5 Debian 192
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 81
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,280)

CVE-2021-43579
7.8

CVE-2021-43579 is a stack-based buffer overflow vulnerability in HTMLDOC's BMP image processing function that allows remote code execution when proces...

Jan 10, 2022
CVE-2021-22045
7.8

This CVE describes a heap-overflow vulnerability in VMware's CD-ROM device emulation that could allow a malicious actor with access to a virtual machi...

Jan 4, 2022
CVE-2021-45926
7.8

CVE-2021-45926 is a stack-based buffer overflow vulnerability in MDB Tools (mdbtools) that allows attackers to execute arbitrary code or cause denial ...

Jan 1, 2022
CVE-2021-45907
7.8

CVE-2021-45907 is a stack-based buffer overflow vulnerability in gif2apng 1.9 that occurs during GIF to APNG conversion. While attackers have limited ...

Dec 28, 2021
CVE-2021-45909
7.8

CVE-2021-45909 is a heap-based buffer overflow vulnerability in gif2apng's DecodeLZW function that allows attackers to write arbitrary data beyond buf...

Dec 28, 2021
CVE-2021-45911
7.8

CVE-2021-45911 is a heap-based buffer overflow vulnerability in gif2apng 1.9 that allows attackers to write 2 bytes outside buffer boundaries. This af...

Dec 28, 2021
CVE-2021-44181
7.8

Adobe Dimension versions 3.4.3 and earlier contain an out-of-bounds write vulnerability in GIF file processing. Attackers can exploit this by tricking...

Dec 20, 2021
CVE-2021-38419
7.8

This vulnerability in Fuji Electric V-Server Lite and Tellus Lite V-Simulator allows attackers to write data beyond allocated memory boundaries, poten...

Dec 20, 2021
CVE-2021-45078
7.8

This vulnerability in GNU Binutils allows attackers to trigger a heap-based buffer overflow via the stab_xcoff_builtin_type function in stabs.c. It ca...

Dec 15, 2021
CVE-2021-1044
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the identity support component. Attackers ca...

Dec 15, 2021
CVE-2021-0675
7.8

CVE-2021-0675 is an out-of-bounds write vulnerability in the ALAC (Apple Lossless Audio Codec) decoder used in MediaTek chipsets. This allows local at...

Dec 15, 2021
CVE-2021-43247
7.8

This vulnerability in the Windows TCP/IP driver allows an attacker to execute arbitrary code with elevated SYSTEM privileges. It affects Windows syste...

Dec 15, 2021
CVE-2021-44434
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. An attacker could execut...

Dec 14, 2021
CVE-2021-44437
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44441
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44443
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK products. Attackers can exploit an...

Dec 14, 2021
CVE-2021-44449
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK libraries. Attackers can exploit a...

Dec 14, 2021
CVE-2021-44001
7.8

This vulnerability allows remote code execution through specially crafted PDF files in Siemens JT2Go and Teamcenter Visualization software. Attackers ...

Dec 14, 2021
CVE-2021-44005
7.8

This vulnerability allows remote code execution through specially crafted TIFF files in Siemens JT2Go and Teamcenter Visualization software. Attackers...

Dec 14, 2021
CVE-2021-44013
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT2Go and Teamcenter Visualization software. Attackers c...

Dec 14, 2021
CVE-2021-42024
7.8

CVE-2021-42024 is an out-of-bounds write vulnerability in Simcenter STAR-CCM+ Viewer that allows remote code execution when parsing malicious scene fi...

Dec 14, 2021
CVE-2021-39049
7.8

CVE-2021-39049 is a stack-based buffer overflow vulnerability in IBM i2 Analyst's Notebook that allows a local attacker to execute arbitrary code with...

Dec 13, 2021
CVE-2021-44045
7.8

This vulnerability allows remote code execution through specially crafted DGN files in Open Design Alliance Drawings SDK. Attackers can exploit an out...

Dec 5, 2021
CVE-2021-29326
7.8

CVE-2021-29326 is a heap buffer overflow vulnerability in Moddable's fxIDToString function that allows attackers to execute arbitrary code or cause de...

Nov 19, 2021
CVE-2021-42524
7.8

CVE-2021-42524 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious BMP file. T...

Nov 18, 2021
CVE-2021-42271
7.8

CVE-2021-42271 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious BMP file. T...

Nov 18, 2021
CVE-2020-12893
7.8

A stack buffer overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with kernel privileges. This af...

Nov 15, 2021
CVE-2020-12903
7.8

This vulnerability in AMD Graphics Driver for Windows 10 allows attackers to write or read outside intended memory boundaries through Escape 0x6002d03...

Nov 15, 2021
CVE-2020-12898
7.8

A stack buffer overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with elevated privileges. This ...

Nov 15, 2021
CVE-2020-12895
7.8

A pool/heap overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with kernel privileges. This affec...

Nov 15, 2021
CVE-2021-43280
7.8

CVE-2021-43280 is a stack-based buffer overflow vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing m...

Nov 14, 2021
CVE-2021-43390
7.8

CVE-2021-43390 is an out-of-bounds write vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing maliciou...

Nov 14, 2021
CVE-2021-30824
7.8

This is a macOS kernel memory corruption vulnerability that allows malicious applications to execute arbitrary code with kernel privileges. It affects...

Oct 28, 2021
CVE-2020-9897
7.8

This vulnerability allows arbitrary code execution through malicious PDF files due to an out-of-bounds write in Apple's PDF processing. It affects iOS...

Oct 28, 2021
CVE-2021-30814
7.8

CVE-2021-30814 is a memory corruption vulnerability in Apple's image processing that allows arbitrary code execution when processing malicious images....

Oct 28, 2021
CVE-2021-42012
7.8

A stack-based buffer overflow vulnerability in Trend Micro Apex One and Worry-Free Business Security allows a local attacker with low-privileged code ...

Oct 21, 2021
CVE-2021-1959
7.8

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to improper input validation when handling index values. Attackers cou...

Oct 20, 2021
CVE-2021-30832
7.8

CVE-2021-30832 is a memory corruption vulnerability in macOS that allows local attackers to escalate privileges. This affects macOS Catalina and Big S...

Oct 19, 2021
CVE-2021-30846
7.8

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....

Oct 19, 2021
CVE-2021-30848
7.8

CVE-2021-30848 is a memory corruption vulnerability in Apple's WebKit browser engine that allows remote code execution when processing malicious web c...

Oct 19, 2021
CVE-2021-30807
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Oct 19, 2021
CVE-2021-28021
7.8

This CVE describes a buffer overflow vulnerability in the stb_image.h library's JPEG parsing function. Attackers can exploit it by crafting a maliciou...

Oct 15, 2021
CVE-2021-40731
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious JPEG2000 file in vulnerable Adobe Acrobat Reader versions. Attackers ...

Oct 15, 2021
CVE-2021-38098
7.8

CVE-2021-38098 is a heap corruption vulnerability in Corel PDF Fusion 2.6.2.0 that allows arbitrary code execution when a user opens a malicious PDF f...

Oct 1, 2021
CVE-2021-38101
7.8

Corel PhotoPaint Standard 2020 contains an out-of-bounds write vulnerability in CDRRip.dll when parsing malicious CPT files. This allows unauthenticat...

Oct 1, 2021
CVE-2021-38110
7.8

CVE-2021-38110 is an out-of-bounds write vulnerability in Corel WordPerfect's Word97Import200.dll that allows arbitrary code execution when parsing ma...

Oct 1, 2021
CVE-2021-38103
7.8

CVE-2021-38103 is an out-of-bounds write vulnerability in Corel Presentations 2020's IBJPG2.FLT filter. When a user opens a malicious PPT file, an att...

Oct 1, 2021
CVE-2021-38096
7.8

CVE-2021-38096 is an out-of-bounds write vulnerability in Corel PDF Fusion's coreip.dll that allows arbitrary code execution when parsing malicious PD...

Oct 1, 2021
CVE-2021-38097
7.8

CVE-2021-38097 is an out-of-bounds write vulnerability in Corel PDF Fusion 2.6.2.0 that allows arbitrary code execution when parsing malicious PDF fil...

Oct 1, 2021
CVE-2021-39829
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Framemaker that allows arbitrary code execution when a user opens a malicious PDF fil...

Sep 29, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,280 CVEs classified as CWE-787, with 812 rated critical and 2,255 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free