CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,331)
This vulnerability is a stack buffer overflow in GPAC's DumpRawUIConfig function that allows remote code execution when processing malicious files. At...
Sep 20, 2021This buffer overflow vulnerability in GPAC's gf_fprintf function allows attackers to execute arbitrary code by exploiting improper bounds checking. It...
Sep 20, 2021Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) has a memory corruption vulnerability when parsing project files, allowing attackers to execute...
Sep 17, 2021This CVE describes a memory corruption vulnerability in Autodesk Navisworks PDF file processing that could allow remote code execution. Attackers can ...
Sep 15, 2021CVE-2021-36952 is a remote code execution vulnerability in Visual Studio that allows attackers to execute arbitrary code by tricking a user into openi...
Sep 15, 2021This vulnerability in Simcenter STAR-CCM+ Viewer allows attackers to execute arbitrary code by exploiting improper validation of scene files. It affec...
Sep 14, 2021This vulnerability is a heap buffer overflow in GPAC's MP4Box tool that allows attackers to cause denial of service or execute arbitrary code by provi...
Sep 13, 2021CVE-2021-30675 is a memory corruption vulnerability in Apple's Boot Camp software that allows a malicious application to elevate privileges. This affe...
Sep 8, 2021This CVE describes an out-of-bounds write vulnerability in Apple operating systems that could allow arbitrary code execution when processing malicious...
Sep 8, 2021This memory corruption vulnerability in macOS allows malicious applications to gain root privileges through improper state management. It affects macO...
Sep 8, 2021This is a memory corruption vulnerability in macOS that allows arbitrary code execution when opening malicious files. It affects macOS Big Sur, Catali...
Sep 8, 2021This vulnerability allows arbitrary code execution by processing a maliciously crafted image file. It affects Apple devices running outdated operating...
Sep 8, 2021CVE-2021-1840 is a memory corruption vulnerability in macOS that allows local attackers to elevate their privileges. This affects macOS Big Sur, Catal...
Sep 8, 2021This vulnerability allows an attacker to execute arbitrary code or crash applications by tricking users into opening a malicious USD (Universal Scene ...
Sep 8, 2021This vulnerability allows arbitrary code execution through malicious image processing. An attacker can craft a malicious image that triggers an out-of...
Sep 8, 2021This is a macOS kernel vulnerability that allows an application to write data beyond allocated memory boundaries. Successful exploitation could enable...
Sep 8, 2021CVE-2021-30739 is a local privilege escalation vulnerability in macOS caused by a memory corruption issue. A local attacker could exploit this to gain...
Sep 8, 2021This vulnerability allows attackers to execute arbitrary code by tricking users into processing a maliciously crafted image. It affects Apple iOS, iPa...
Sep 8, 2021CVE-2021-30748 is a memory corruption vulnerability in Apple's iOS and macOS kernels that allows an application to execute arbitrary code with kernel ...
Sep 8, 2021This macOS kernel vulnerability allows malicious applications to write beyond allocated memory boundaries, potentially executing arbitrary code with k...
Sep 8, 2021This vulnerability allows a malicious application to write data beyond allocated memory bounds in macOS kernel components, potentially leading to arbi...
Sep 8, 2021This vulnerability allows an attacker to trigger a heap-based buffer overflow by providing a malicious NTFS image to NTFS-3G. Systems using NTFS-3G ve...
Sep 7, 2021This vulnerability in NTFS-3G allows attackers to trigger an out-of-bounds memory access by providing a malicious NTFS image. When exploited, it can l...
Sep 7, 2021CVE-2021-39262 is an out-of-bounds memory access vulnerability in NTFS-3G's decompression function that can be triggered by a specially crafted NTFS i...
Sep 7, 2021A heap buffer overflow vulnerability in NTFS-3G allows attackers to write to arbitrary memory or cause denial of service when reading specially crafte...
Sep 7, 2021A stack buffer overflow vulnerability in NTFS-3G versions before 2021.8.22 allows local attackers to execute arbitrary code or escalate privileges whe...
Sep 7, 2021A heap buffer overflow vulnerability in NTFS-3G allows memory disclosure or denial of service when mounting a specially crafted NTFS partition. Attack...
Sep 7, 2021This vulnerability allows attackers to execute arbitrary code and escalate privileges by exploiting a heap buffer overflow in NTFS-3G when processing ...
Sep 7, 2021Adobe After Effects versions 18.2.1 and earlier contain an out-of-bounds write vulnerability when parsing malicious files. An attacker can achieve arb...
Sep 2, 2021CVE-2021-21086 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC's CoolType library that allows arbitrary code execution when a user ...
Sep 2, 2021This CVE describes an out-of-bounds write vulnerability in Adobe Photoshop that could allow an attacker to execute arbitrary code on a victim's system...
Sep 1, 2021CVE-2021-36072 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...
Sep 1, 2021This vulnerability allows malicious iOS/iPadOS applications to write data beyond allocated memory boundaries, potentially leading to arbitrary code ex...
Aug 24, 2021This vulnerability allows attackers to execute arbitrary code or crash applications by tricking users into opening malicious USD (Universal Scene Desc...
Aug 24, 2021This memory corruption vulnerability in Apple's ColorSync ICC profile processing allows arbitrary code execution when processing malicious images. It ...
Aug 24, 2021This CVE describes a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel p...
Aug 24, 2021This is a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel privileges. ...
Aug 24, 2021This is a memory corruption vulnerability in iOS/iPadOS that allows malicious applications to execute arbitrary code with kernel privileges. It affect...
Aug 24, 2021CVE-2021-30916 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...
Aug 24, 2021This vulnerability allows arbitrary code execution through malicious PDF files due to an out-of-bounds write in Apple's PDF processing. It affects mul...
Aug 24, 2021This CVE describes multiple out-of-bounds write vulnerabilities in macOS that could allow a malicious application to execute arbitrary code with kerne...
Aug 24, 2021This vulnerability allows malicious applications to write data beyond allocated memory boundaries in macOS kernel components, potentially leading to a...
Aug 24, 2021This CVE-2021-30909 is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel p...
Aug 24, 2021CVE-2021-30894 is a memory corruption vulnerability in Apple iOS, iPadOS, and tvOS that allows malicious applications to execute arbitrary code with k...
Aug 24, 2021This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...
Aug 24, 2021Adobe Animate versions 21.0.6 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malici...
Aug 24, 2021CVE-2021-32263 is a heap-based buffer overflow vulnerability in ok-file-formats library's CSV parsing functionality. Attackers can exploit this by pro...
Aug 24, 2021Adobe After Effects versions 18.2 and earlier contain a memory corruption vulnerability (CWE-787) that allows arbitrary code execution when a user ope...
Aug 24, 2021CVE-2021-35989 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. Attack...
Aug 20, 2021CVE-2021-28591 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Atta...
Aug 20, 2021About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,331 CVEs classified as CWE-787, with 818 rated critical and 2,300 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free