CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,317
Total CVEs
818
Critical
2,286
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 396
2 Adobe 272
3 Apple 247
4 Linux 231
5 Debian 193
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 81
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,317)

CVE-2020-12893
7.8

A stack buffer overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with kernel privileges. This af...

Nov 15, 2021
CVE-2020-12903
7.8

This vulnerability in AMD Graphics Driver for Windows 10 allows attackers to write or read outside intended memory boundaries through Escape 0x6002d03...

Nov 15, 2021
CVE-2020-12898
7.8

A stack buffer overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with elevated privileges. This ...

Nov 15, 2021
CVE-2020-12895
7.8

A pool/heap overflow vulnerability in AMD Graphics Driver for Windows 10 allows attackers to execute arbitrary code with kernel privileges. This affec...

Nov 15, 2021
CVE-2021-43280
7.8

CVE-2021-43280 is a stack-based buffer overflow vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing m...

Nov 14, 2021
CVE-2021-43390
7.8

CVE-2021-43390 is an out-of-bounds write vulnerability in Open Design Alliance Drawings SDK that allows remote code execution when processing maliciou...

Nov 14, 2021
CVE-2021-30824
7.8

This is a macOS kernel memory corruption vulnerability that allows malicious applications to execute arbitrary code with kernel privileges. It affects...

Oct 28, 2021
CVE-2020-9897
7.8

This vulnerability allows arbitrary code execution through malicious PDF files due to an out-of-bounds write in Apple's PDF processing. It affects iOS...

Oct 28, 2021
CVE-2021-30814
7.8

CVE-2021-30814 is a memory corruption vulnerability in Apple's image processing that allows arbitrary code execution when processing malicious images....

Oct 28, 2021
CVE-2021-42012
7.8

A stack-based buffer overflow vulnerability in Trend Micro Apex One and Worry-Free Business Security allows a local attacker with low-privileged code ...

Oct 21, 2021
CVE-2021-1959
7.8

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to improper input validation when handling index values. Attackers cou...

Oct 20, 2021
CVE-2021-30832
7.8

CVE-2021-30832 is a memory corruption vulnerability in macOS that allows local attackers to escalate privileges. This affects macOS Catalina and Big S...

Oct 19, 2021
CVE-2021-30846
7.8

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content....

Oct 19, 2021
CVE-2021-30848
7.8

CVE-2021-30848 is a memory corruption vulnerability in Apple's WebKit browser engine that allows remote code execution when processing malicious web c...

Oct 19, 2021
CVE-2021-30807
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Oct 19, 2021
CVE-2021-28021
7.8

This CVE describes a buffer overflow vulnerability in the stb_image.h library's JPEG parsing function. Attackers can exploit it by crafting a maliciou...

Oct 15, 2021
CVE-2021-40731
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious JPEG2000 file in vulnerable Adobe Acrobat Reader versions. Attackers ...

Oct 15, 2021
CVE-2021-38098
7.8

CVE-2021-38098 is a heap corruption vulnerability in Corel PDF Fusion 2.6.2.0 that allows arbitrary code execution when a user opens a malicious PDF f...

Oct 1, 2021
CVE-2021-38101
7.8

Corel PhotoPaint Standard 2020 contains an out-of-bounds write vulnerability in CDRRip.dll when parsing malicious CPT files. This allows unauthenticat...

Oct 1, 2021
CVE-2021-38110
7.8

CVE-2021-38110 is an out-of-bounds write vulnerability in Corel WordPerfect's Word97Import200.dll that allows arbitrary code execution when parsing ma...

Oct 1, 2021
CVE-2021-38103
7.8

CVE-2021-38103 is an out-of-bounds write vulnerability in Corel Presentations 2020's IBJPG2.FLT filter. When a user opens a malicious PPT file, an att...

Oct 1, 2021
CVE-2021-38096
7.8

CVE-2021-38096 is an out-of-bounds write vulnerability in Corel PDF Fusion's coreip.dll that allows arbitrary code execution when parsing malicious PD...

Oct 1, 2021
CVE-2021-38097
7.8

CVE-2021-38097 is an out-of-bounds write vulnerability in Corel PDF Fusion 2.6.2.0 that allows arbitrary code execution when parsing malicious PDF fil...

Oct 1, 2021
CVE-2021-39829
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Framemaker that allows arbitrary code execution when a user opens a malicious PDF fil...

Sep 29, 2021
CVE-2021-39831
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Framemaker that allows arbitrary code execution when a user opens a malicious PDF fil...

Sep 29, 2021
CVE-2021-29360
7.8

This buffer overflow vulnerability in IrfanView allows attackers to execute arbitrary code by tricking users into opening a specially crafted RLE imag...

Sep 28, 2021
CVE-2021-29362
7.8

A buffer overflow vulnerability in IrfanView's RLE file parser allows attackers to execute arbitrary code by tricking users into opening a specially c...

Sep 28, 2021
CVE-2021-29364
7.8

This buffer overflow vulnerability in IrfanView allows attackers to execute arbitrary code by tricking users into opening a specially crafted RLE imag...

Sep 28, 2021
CVE-2021-29366
7.8

A buffer overflow vulnerability in IrfanView 4.57 allows attackers to execute arbitrary code by tricking users into opening a specially crafted RLE im...

Sep 28, 2021
CVE-2021-39825
7.8

This vulnerability in Adobe Photoshop Elements allows attackers to execute arbitrary code on a victim's computer by tricking them into opening a malic...

Sep 27, 2021
CVE-2021-39595
7.8

This vulnerability in swftools allows attackers to execute arbitrary code through a stack buffer overflow in the rfx_alloc() function. It affects all ...

Sep 20, 2021
CVE-2021-39550
7.8

CVE-2021-39550 is a heap-based buffer overflow vulnerability in sela's file reading function that allows attackers to execute arbitrary code or cause ...

Sep 20, 2021
CVE-2021-39552
7.8

CVE-2021-39552 is a heap-based buffer overflow vulnerability in sela's WAV file parsing function. Attackers can exploit this by crafting malicious WAV...

Sep 20, 2021
CVE-2021-39558
7.8

This vulnerability in swftools allows attackers to execute arbitrary code through a stack buffer overflow when processing malicious SWF files. It affe...

Sep 20, 2021
CVE-2021-39561
7.8

CVE-2021-39561 is a stack buffer overflow vulnerability in swftools that allows remote code execution when processing malicious SWF files. Attackers c...

Sep 20, 2021
CVE-2021-39564
7.8

CVE-2021-39564 is a heap buffer overflow vulnerability in swftools that allows attackers to execute arbitrary code by exploiting the swf_DumpActions()...

Sep 20, 2021
CVE-2021-39574
7.8

This vulnerability is a heap buffer overflow in swftools' pool_read() function that allows attackers to execute arbitrary code. It affects all users o...

Sep 20, 2021
CVE-2021-39577
7.8

CVE-2021-39577 is a heap buffer overflow vulnerability in swftools' swfdump utility that allows attackers to execute arbitrary code by providing a mal...

Sep 20, 2021
CVE-2021-39582
7.8

A heap buffer overflow vulnerability in swftools allows attackers to execute arbitrary code by exploiting the swf_GetPlaceObject() function. This affe...

Sep 20, 2021
CVE-2021-39540
7.8

CVE-2021-39540 is a stack buffer overflow vulnerability in pdftools that allows remote code execution when processing malicious PDF files. Attackers c...

Sep 20, 2021
CVE-2021-39544
7.8

CVE-2021-39544 is a heap-based buffer overflow vulnerability in sela's WAV file writing function. Attackers can exploit this by crafting malicious WAV...

Sep 20, 2021
CVE-2021-39546
7.8

CVE-2021-39546 is a heap-based buffer overflow vulnerability in the sela audio library's RiceDecoder::process() function. Attackers can exploit this t...

Sep 20, 2021
CVE-2021-32273
7.8

CVE-2021-32273 is a stack buffer overflow vulnerability in the ftypin function of faad2 MP4/AAC audio decoder library. It allows remote attackers to e...

Sep 20, 2021
CVE-2021-32277
7.8

This vulnerability in faad2 audio decoding library allows heap buffer overflow in the sbr_qmf_analysis_32 function, potentially enabling remote code e...

Sep 20, 2021
CVE-2021-32281
7.8

CVE-2021-32281 is a heap buffer overflow vulnerability in Gravity programming language's AST parser that allows attackers to execute arbitrary code. T...

Sep 20, 2021
CVE-2021-32286
7.8

CVE-2021-32286 is a critical buffer overflow vulnerability in hcxtools that allows remote code execution when processing malicious pcapng files. Attac...

Sep 20, 2021
CVE-2021-32288
7.8

This vulnerability is a heap buffer overflow in the HEIF library's HEVC decoder configuration record parser. Attackers can exploit this to execute arb...

Sep 20, 2021
CVE-2021-32271
7.8

This vulnerability is a stack buffer overflow in GPAC's DumpRawUIConfig function that allows remote code execution when processing malicious files. At...

Sep 20, 2021
CVE-2021-32268
7.8

This buffer overflow vulnerability in GPAC's gf_fprintf function allows attackers to execute arbitrary code by exploiting improper bounds checking. It...

Sep 20, 2021
CVE-2021-38406
7.8

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) has a memory corruption vulnerability when parsing project files, allowing attackers to execute...

Sep 17, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,317 CVEs classified as CWE-787, with 818 rated critical and 2,286 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free