CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,352
Total CVEs
837
Critical
2,302
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 399
2 Adobe 287
3 Apple 247
4 Linux 231
5 Debian 194
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 85
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,352)

CVE-2021-36072
7.8

CVE-2021-36072 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. This a...

Sep 1, 2021
CVE-2021-30985
7.8

This vulnerability allows malicious iOS/iPadOS applications to write data beyond allocated memory boundaries, potentially leading to arbitrary code ex...

Aug 24, 2021
CVE-2021-30971
7.8

This vulnerability allows attackers to execute arbitrary code or crash applications by tricking users into opening malicious USD (Universal Scene Desc...

Aug 24, 2021
CVE-2021-30942
7.8

This memory corruption vulnerability in Apple's ColorSync ICC profile processing allows arbitrary code execution when processing malicious images. It ...

Aug 24, 2021
CVE-2021-30949
7.8

This CVE describes a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel p...

Aug 24, 2021
CVE-2021-30937
7.8

This is a memory corruption vulnerability in Apple's XNU kernel that allows a malicious application to execute arbitrary code with kernel privileges. ...

Aug 24, 2021
CVE-2021-30914
7.8

This is a memory corruption vulnerability in iOS/iPadOS that allows malicious applications to execute arbitrary code with kernel privileges. It affect...

Aug 24, 2021
CVE-2021-30916
7.8

CVE-2021-30916 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to execute arbitrary code with kerne...

Aug 24, 2021
CVE-2021-30919
7.8

This vulnerability allows arbitrary code execution through malicious PDF files due to an out-of-bounds write in Apple's PDF processing. It affects mul...

Aug 24, 2021
CVE-2021-30922
7.8

This CVE describes multiple out-of-bounds write vulnerabilities in macOS that could allow a malicious application to execute arbitrary code with kerne...

Aug 24, 2021
CVE-2021-30901
7.8

This vulnerability allows malicious applications to write data beyond allocated memory boundaries in macOS kernel components, potentially leading to a...

Aug 24, 2021
CVE-2021-30909
7.8

This CVE-2021-30909 is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel p...

Aug 24, 2021
CVE-2021-30894
7.8

CVE-2021-30894 is a memory corruption vulnerability in Apple iOS, iPadOS, and tvOS that allows malicious applications to execute arbitrary code with k...

Aug 24, 2021
CVE-2021-30883
7.8

This is a memory corruption vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges. It a...

Aug 24, 2021
CVE-2021-28622
7.8

Adobe Animate versions 21.0.6 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution when a user opens a malici...

Aug 24, 2021
CVE-2021-32263
7.8

CVE-2021-32263 is a heap-based buffer overflow vulnerability in ok-file-formats library's CSV parsing functionality. Attackers can exploit this by pro...

Aug 24, 2021
CVE-2021-28602
7.8

Adobe After Effects versions 18.2 and earlier contain a memory corruption vulnerability (CWE-787) that allows arbitrary code execution when a user ope...

Aug 24, 2021
CVE-2021-35989
7.8

CVE-2021-35989 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious file. Attack...

Aug 20, 2021
CVE-2021-28591
7.8

CVE-2021-28591 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Atta...

Aug 20, 2021
CVE-2021-0646
7.8

This vulnerability allows local privilege escalation on Android devices through SQLite's printf formatting function. An attacker can execute arbitrary...

Aug 17, 2021
CVE-2021-0573
7.8

CVE-2021-0573 is an out-of-bounds write vulnerability in Android's ASF extractor component that allows local privilege escalation without user interac...

Aug 17, 2021
CVE-2021-0576
7.8

CVE-2021-0576 is an out-of-bounds write vulnerability in Android's FLV extractor component that allows local privilege escalation without user interac...

Aug 17, 2021
CVE-2021-0640
7.8

CVE-2021-0640 is an out-of-bounds write vulnerability in Android's StatsdStats.cpp that allows local privilege escalation without user interaction. It...

Aug 17, 2021
CVE-2021-21813
7.8

CVE-2021-21813 is a stack-buffer overflow vulnerability in the HandleFileArg function where user-controlled command-line input is copied without lengt...

Aug 13, 2021
CVE-2021-21815
7.8

This vulnerability allows attackers to execute arbitrary code on systems running Xmill 0.7 by exploiting a stack-based buffer overflow in the command-...

Aug 13, 2021
CVE-2020-19491
7.8

CVE-2020-19491 is an invalid memory access vulnerability in the cgif.c component of sam2p image conversion software that causes a segmentation fault w...

Jul 21, 2021
CVE-2019-25050
7.8

This CVE describes a stack-based buffer overflow vulnerability in netCDF component of GDAL software. Attackers can exploit this to execute arbitrary c...

Jul 20, 2021
CVE-2020-36430
7.8

CVE-2020-36430 is a heap-based buffer overflow vulnerability in libass subtitle library versions 0.15.x before 0.15.1. The vulnerability occurs due to...

Jul 20, 2021
CVE-2021-0577
7.8

CVE-2021-0577 is a heap buffer overflow vulnerability in Android's FLV extractor component that allows local privilege escalation without user interac...

Jul 14, 2021
CVE-2021-0589
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the Bluetooth stack. An attacker with user e...

Jul 14, 2021
CVE-2021-34319
7.8

This vulnerability allows remote code execution through specially crafted SGI image files in Siemens JT2Go and Teamcenter Visualization software. Atta...

Jul 13, 2021
CVE-2021-34323
7.8

This vulnerability allows remote code execution through specially crafted JT files in Siemens JT2Go and Teamcenter Visualization software. Attackers c...

Jul 13, 2021
CVE-2021-34305
7.8

This vulnerability allows remote code execution through malicious GIF files in Siemens JT2Go and Teamcenter Visualization software. Attackers can expl...

Jul 13, 2021
CVE-2021-34309
7.8

This vulnerability allows remote code execution through malicious TIFF files in Siemens JT2Go and Teamcenter Visualization software. Attackers can exp...

Jul 13, 2021
CVE-2021-34311
7.8

This vulnerability allows remote code execution through specially crafted J2K files in Siemens JT2Go and Teamcenter Visualization software. Attackers ...

Jul 13, 2021
CVE-2021-34291
7.8

This vulnerability allows remote code execution through malicious GIF files in Siemens JT2Go and Teamcenter Visualization software. Attackers can expl...

Jul 13, 2021
CVE-2021-34293
7.8

This vulnerability allows remote code execution through malicious GIF files in Siemens JT2Go and Teamcenter Visualization software. Attackers can expl...

Jul 13, 2021
CVE-2021-34295
7.8

This vulnerability allows remote code execution through malicious GIF files in Siemens JT2Go and Teamcenter Visualization software. Attackers can expl...

Jul 13, 2021
CVE-2021-34297
7.8

This vulnerability allows remote code execution through malicious BMP files in Siemens JT2Go and Teamcenter Visualization software. Attackers can expl...

Jul 13, 2021
CVE-2021-34300
7.8

This vulnerability allows remote code execution through specially crafted TIFF files in Siemens JT2Go and Teamcenter Visualization software. Attackers...

Jul 13, 2021
CVE-2021-33792
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds write vulnerability in Foxit Reader and PhantomPDF when p...

Jul 9, 2021
CVE-2021-27036
7.8

This is a buffer overflow vulnerability in Autodesk software that allows arbitrary code execution when processing malicious image files. Attackers can...

Jul 9, 2021
CVE-2021-27034
7.8

This heap-based buffer overflow vulnerability in Autodesk Design Review allows attackers to execute arbitrary code by tricking users into opening mali...

Jul 9, 2021
CVE-2020-36402
7.8

This CVE describes a stack-use-after-return vulnerability in Solidity 0.7.5's SMT solver interface. It could allow attackers to cause memory corruptio...

Jul 1, 2021
CVE-2021-21871
7.8

This vulnerability allows an attacker to execute arbitrary code on systems running vulnerable versions of PowerISO by tricking users into opening a sp...

Jun 29, 2021
CVE-2021-31509
7.8

CVE-2021-31509 is a buffer overflow vulnerability in OpenText Brava! Desktop that allows remote code execution when processing malicious DXF files. At...

Jun 29, 2021
CVE-2021-31511
7.8

CVE-2021-31511 is a heap-based buffer overflow vulnerability in OpenText Brava! Desktop's PDF parser that allows remote code execution. Attackers can ...

Jun 29, 2021
CVE-2021-31513
7.8

CVE-2021-31513 is a buffer overflow vulnerability in OpenText Brava! Desktop's BMP file parser that allows remote code execution. Attackers can exploi...

Jun 29, 2021
CVE-2021-28586
7.8

CVE-2021-28586 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Jun 28, 2021
CVE-2021-0607
7.8

This vulnerability allows local attackers to write arbitrary data to hardware ports due to missing bounds checks in the iaxxx-codec driver. It enables...

Jun 22, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,352 CVEs classified as CWE-787, with 837 rated critical and 2,302 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free