CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,331
Total CVEs
818
Critical
2,300
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 399
2 Adobe 273
3 Apple 247
4 Linux 231
5 Debian 193
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 85
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,331)

CVE-2021-32271
7.8

This vulnerability is a stack buffer overflow in GPAC's DumpRawUIConfig function that allows remote code execution when processing malicious files. At...

Sep 20, 2021
CVE-2021-32268
7.8

This buffer overflow vulnerability in GPAC's gf_fprintf function allows attackers to execute arbitrary code by exploiting improper bounds checking. It...

Sep 20, 2021
CVE-2021-38406
7.8

Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) has a memory corruption vulnerability when parsing project files, allowing attackers to execute...

Sep 17, 2021
CVE-2021-27046
7.8

This CVE describes a memory corruption vulnerability in Autodesk Navisworks PDF file processing that could allow remote code execution. Attackers can ...

Sep 15, 2021
CVE-2021-36952
7.8

CVE-2021-36952 is a remote code execution vulnerability in Visual Studio that allows attackers to execute arbitrary code by tricking a user into openi...

Sep 15, 2021
CVE-2021-25665
7.8

This vulnerability in Simcenter STAR-CCM+ Viewer allows attackers to execute arbitrary code by exploiting improper validation of scene files. It affec...

Sep 14, 2021
CVE-2021-32136
7.8

This vulnerability is a heap buffer overflow in GPAC's MP4Box tool that allows attackers to cause denial of service or execute arbitrary code by provi...

Sep 13, 2021
CVE-2021-30675
7.8

CVE-2021-30675 is a memory corruption vulnerability in Apple's Boot Camp software that allows a malicious application to elevate privileges. This affe...

Sep 8, 2021
CVE-2021-30664
7.8

This CVE describes an out-of-bounds write vulnerability in Apple operating systems that could allow arbitrary code execution when processing malicious...

Sep 8, 2021
CVE-2021-30672
7.8

This memory corruption vulnerability in macOS allows malicious applications to gain root privileges through improper state management. It affects macO...

Sep 8, 2021
CVE-2021-1847
7.8

This is a memory corruption vulnerability in macOS that allows arbitrary code execution when opening malicious files. It affects macOS Big Sur, Catali...

Sep 8, 2021
CVE-2021-1858
7.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted image file. It affects Apple devices running outdated operating...

Sep 8, 2021
CVE-2021-1840
7.8

CVE-2021-1840 is a memory corruption vulnerability in macOS that allows local attackers to elevate their privileges. This affects macOS Big Sur, Catal...

Sep 8, 2021
CVE-2021-1762
7.8

This vulnerability allows an attacker to execute arbitrary code or crash applications by tricking users into opening a malicious USD (Universal Scene ...

Sep 8, 2021
CVE-2021-30792
7.8

This vulnerability allows arbitrary code execution through malicious image processing. An attacker can craft a malicious image that triggers an out-of...

Sep 8, 2021
CVE-2021-30766
7.8

This is a macOS kernel vulnerability that allows an application to write data beyond allocated memory boundaries. Successful exploitation could enable...

Sep 8, 2021
CVE-2021-30739
7.8

CVE-2021-30739 is a local privilege escalation vulnerability in macOS caused by a memory corruption issue. A local attacker could exploit this to gain...

Sep 8, 2021
CVE-2021-30743
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into processing a maliciously crafted image. It affects Apple iOS, iPa...

Sep 8, 2021
CVE-2021-30748
7.8

CVE-2021-30748 is a memory corruption vulnerability in Apple's iOS and macOS kernels that allows an application to execute arbitrary code with kernel ...

Sep 8, 2021
CVE-2021-30726
7.8

This macOS kernel vulnerability allows malicious applications to write beyond allocated memory boundaries, potentially executing arbitrary code with k...

Sep 8, 2021
CVE-2021-30728
7.8

This vulnerability allows a malicious application to write data beyond allocated memory bounds in macOS kernel components, potentially leading to arbi...

Sep 8, 2021
CVE-2021-39256
7.8

This vulnerability allows an attacker to trigger a heap-based buffer overflow by providing a malicious NTFS image to NTFS-3G. Systems using NTFS-3G ve...

Sep 7, 2021
CVE-2021-39260
7.8

This vulnerability in NTFS-3G allows attackers to trigger an out-of-bounds memory access by providing a malicious NTFS image. When exploited, it can l...

Sep 7, 2021
CVE-2021-39262
7.8

CVE-2021-39262 is an out-of-bounds memory access vulnerability in NTFS-3G's decompression function that can be triggered by a specially crafted NTFS i...

Sep 7, 2021
CVE-2021-33287
7.8

A heap buffer overflow vulnerability in NTFS-3G allows attackers to write to arbitrary memory or cause denial of service when reading specially crafte...

Sep 7, 2021
CVE-2021-35267
7.8

A stack buffer overflow vulnerability in NTFS-3G versions before 2021.8.22 allows local attackers to execute arbitrary code or escalate privileges whe...

Sep 7, 2021
CVE-2021-33285
7.8

A heap buffer overflow vulnerability in NTFS-3G allows memory disclosure or denial of service when mounting a specially crafted NTFS partition. Attack...

Sep 7, 2021
CVE-2021-35268
7.8

This vulnerability allows attackers to execute arbitrary code and escalate privileges by exploiting a heap buffer overflow in NTFS-3G when processing ...

Sep 7, 2021
CVE-2021-35993
7.8

Adobe After Effects versions 18.2.1 and earlier contain an out-of-bounds write vulnerability when parsing malicious files. An attacker can achieve arb...

Sep 2, 2021
CVE-2021-21086
7.8

CVE-2021-21086 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC's CoolType library that allows arbitrary code execution when a user ...

Sep 2, 2021
CVE-2021-36066
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow an attacker to execute arbitrary code on a victim's system...

Sep 1, 2021
CVE-2021-36072
7.8

CVE-2021-36072 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...

Sep 1, 2021
CVE-2021-30985
7.8

This vulnerability allows malicious iOS/iPadOS applications to write data beyond allocated memory boundaries, potentially leading to arbitrary code ex...

Aug 24, 2021
CVE-2021-30971
7.8

This vulnerability allows attackers to execute arbitrary code or crash applications by tricking users into opening malicious USD (Universal Scene Desc...

Aug 24, 2021
CVE-2021-30942
7.8

This memory corruption vulnerability in Apple's ColorSync ICC profile processing allows arbitrary code execution when processing malicious images. It ...

Aug 24, 2021
CVE-2021-30949
7.8

This CVE describes a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel p...

Aug 24, 2021
CVE-2021-30937
7.8

This is a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel privileges. ...

Aug 24, 2021
CVE-2021-30914
7.8

This is a memory corruption vulnerability in iOS/iPadOS that allows malicious applications to execute arbitrary code with kernel privileges. It affect...

Aug 24, 2021
CVE-2021-30916
7.8

CVE-2021-30916 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...

Aug 24, 2021
CVE-2021-30919
7.8

This vulnerability allows arbitrary code execution through malicious PDF files due to an out-of-bounds write in Apple's PDF processing. It affects mul...

Aug 24, 2021
CVE-2021-30922
7.8

This CVE describes multiple out-of-bounds write vulnerabilities in macOS that could allow a malicious application to execute arbitrary code with kerne...

Aug 24, 2021
CVE-2021-30901
7.8

This vulnerability allows malicious applications to write data beyond allocated memory boundaries in macOS kernel components, potentially leading to a...

Aug 24, 2021
CVE-2021-30909
7.8

This CVE-2021-30909 is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel p...

Aug 24, 2021
CVE-2021-30894
7.8

CVE-2021-30894 is a memory corruption vulnerability in Apple iOS, iPadOS, and tvOS that allows malicious applications to execute arbitrary code with k...

Aug 24, 2021
CVE-2021-30883
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Aug 24, 2021
CVE-2021-28622
7.8

Adobe Animate versions 21.0.6 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malici...

Aug 24, 2021
CVE-2021-32263
7.8

CVE-2021-32263 is a heap-based buffer overflow vulnerability in ok-file-formats library's CSV parsing functionality. Attackers can exploit this by pro...

Aug 24, 2021
CVE-2021-28602
7.8

Adobe After Effects versions 18.2 and earlier contain a memory corruption vulnerability (CWE-787) that allows arbitrary code execution when a user ope...

Aug 24, 2021
CVE-2021-35989
7.8

CVE-2021-35989 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. Attack...

Aug 20, 2021
CVE-2021-28591
7.8

CVE-2021-28591 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Atta...

Aug 20, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,331 CVEs classified as CWE-787, with 818 rated critical and 2,300 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free