CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,359
Total CVEs
839
Critical
2,307
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 402
2 Adobe 288
3 Apple 247
4 Linux 232
5 Debian 195
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 85
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,359)

CVE-2021-31509
7.8

CVE-2021-31509 is a buffer overflow vulnerability in OpenText Brava! Desktop that allows remote code execution when processing malicious DXF files. At...

Jun 29, 2021
CVE-2021-31511
7.8

CVE-2021-31511 is a heap-based buffer overflow vulnerability in OpenText Brava! Desktop's PDF parser that allows remote code execution. Attackers can ...

Jun 29, 2021
CVE-2021-31513
7.8

CVE-2021-31513 is a buffer overflow vulnerability in OpenText Brava! Desktop's BMP file parser that allows remote code execution. Attackers can exploi...

Jun 29, 2021
CVE-2021-28586
7.8

CVE-2021-28586 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

Jun 28, 2021
CVE-2021-0607
7.8

This vulnerability allows local attackers to write arbitrary data to hardware ports due to missing bounds checks in the iaxxx-codec driver. It enables...

Jun 22, 2021
CVE-2021-34202
7.8

This vulnerability in D-Link DIR-2640 routers allows local attackers with ordinary user permissions to exploit out-of-bounds memory vulnerabilities to...

Jun 16, 2021
CVE-2021-0489
7.8

This CVE describes a memory management driver vulnerability in Android System-on-Chip (SoC) devices where missing bounds checking allows out-of-bounds...

Jun 11, 2021
CVE-2021-0493
7.8

This vulnerability allows local attackers to write beyond allocated memory boundaries in Android's memory management driver, potentially leading to pr...

Jun 11, 2021
CVE-2021-22750
7.8

This vulnerability allows attackers to execute arbitrary code or cause data loss by exploiting an out-of-bounds write flaw in Schneider Electric's IGS...

Jun 11, 2021
CVE-2021-22752
7.8

This vulnerability allows attackers to execute arbitrary code or cause data loss by exploiting an out-of-bounds write flaw in Schneider Electric's IGS...

Jun 11, 2021
CVE-2021-22754
7.8

This vulnerability allows attackers to execute arbitrary code or cause data loss on systems running vulnerable versions of Schneider Electric's IGSS D...

Jun 11, 2021
CVE-2021-25407
7.8

This vulnerability allows an attacker to write arbitrary data to memory in Samsung's NPU (Neural Processing Unit) driver, potentially leading to syste...

Jun 11, 2021
CVE-2021-27387
7.8

This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting improper validation when parsing FEMAP files. Users of ...

Jun 8, 2021
CVE-2021-27399
7.8

This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting an out-of-bounds write when parsing malicious FEMAP fil...

Jun 8, 2021
CVE-2021-22335
7.8

This is an out-of-bounds write vulnerability (CWE-787) in Huawei smartphone image processing components. Attackers could exploit this to cause memory ...

Jun 3, 2021
CVE-2010-3843
7.8

CVE-2010-3843 is a buffer overflow vulnerability in the GTK interface of ettercap, a network security tool. It allows local attackers to execute arbit...

May 28, 2021
CVE-2021-27488
7.8

This vulnerability allows remote code execution through specially crafted CATPart files in KeyShot 3D rendering software. An attacker can exploit impr...

May 27, 2021
CVE-2021-33200
7.8

This vulnerability in the Linux kernel's BPF verifier allows incorrect pointer arithmetic limits, enabling out-of-bounds memory access. Attackers can ...

May 27, 2021
CVE-2021-32458
7.8

This CVE describes a stack-based buffer overflow vulnerability in Trend Micro Home Network Security, allowing an attacker with low-privileged code exe...

May 27, 2021
CVE-2021-31473
7.8

CVE-2021-31473 is a remote code execution vulnerability in Foxit Reader's browseForDoc function. Attackers can exploit it by tricking users into openi...

May 21, 2021
CVE-2021-32238
7.8

A stack-based buffer overflow vulnerability in Rocket League allows attackers to execute arbitrary code or cause denial of service by crafting malicio...

May 18, 2021
CVE-2020-21813
7.8

CVE-2020-21813 is a heap-based buffer overflow vulnerability in GNU LibreDWG's dwg2SVG converter. Attackers can exploit this by crafting malicious DWG...

May 17, 2021
CVE-2021-28465
7.8

CVE-2021-28465 is a remote code execution vulnerability in Microsoft Web Media Extensions that allows attackers to execute arbitrary code on affected ...

May 11, 2021
CVE-2021-31465
7.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a memory corruption flaw in Foxit Reader's handling of U3D objects ...

May 7, 2021
CVE-2021-31472
7.8

This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening a malicious PDF file containing a ...

May 7, 2021
CVE-2020-28011
7.8

CVE-2020-28011 is a heap-based buffer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. Attackers can exploit this via the -R...

May 6, 2021
CVE-2020-28013
7.8

CVE-2020-28013 is a heap-based buffer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. It allows local privilege escalation ...

May 6, 2021
CVE-2021-31433
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ARW image files in Foxit Studio Photo. I...

Apr 29, 2021
CVE-2021-31437
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files in Foxit Studio Photo. A...

Apr 29, 2021
CVE-2021-20294
7.8

A stack buffer overflow vulnerability in binutils readelf 2.35 allows attackers to execute arbitrary code by tricking users into processing malicious ...

Apr 29, 2021
CVE-2021-22664
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected CNCSoft-B systems by exploiting an out-of-bounds write condition. Ind...

Apr 27, 2021
CVE-2021-25670
7.8

CVE-2021-25670 is an out-of-bounds write vulnerability in Tecnomatix RobotExpert that allows attackers to execute arbitrary code by exploiting imprope...

Apr 22, 2021
CVE-2021-25678
7.8

This vulnerability in Solid Edge CAD software allows attackers to execute arbitrary code by exploiting improper validation of PAR files. It affects So...

Apr 22, 2021
CVE-2020-35979
7.8

This CVE describes a heap-based buffer overflow vulnerability in GPAC's RTP builder function for AVC video. Attackers can exploit this to execute arbi...

Apr 21, 2021
CVE-2021-31254
7.8

CVE-2021-31254 is a buffer overflow vulnerability in GPAC's MP4Box tool that allows attackers to cause denial of service or execute arbitrary code by ...

Apr 19, 2021
CVE-2021-21094
7.8

CVE-2021-21094 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when parsing malicious files. Attackers ca...

Apr 15, 2021
CVE-2021-28310
7.8

CVE-2021-28310 is a Win32k elevation of privilege vulnerability in Windows kernel-mode drivers. It allows authenticated attackers to execute arbitrary...

Apr 13, 2021
CVE-2021-0439
7.8

This vulnerability allows local privilege escalation on Android 11 devices through an out-of-bounds write in the PowerManagerService component. Attack...

Apr 13, 2021
CVE-2021-0426
7.8

This CVE describes a heap buffer overflow vulnerability in Android's LogEvent.cpp that allows local privilege escalation without user interaction. Att...

Apr 13, 2021
CVE-2021-1805
7.8

CVE-2021-1805 is an out-of-bounds write vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. This affec...

Apr 2, 2021
CVE-2021-1767
7.8

A heap corruption vulnerability in Apple's image processing libraries allows attackers to execute arbitrary code by tricking users into opening malici...

Apr 2, 2021
CVE-2021-1772
7.8

This vulnerability allows arbitrary code execution through a stack overflow when processing malicious text files. It affects macOS, iOS, iPadOS, tvOS,...

Apr 2, 2021
CVE-2021-1776
7.8

CVE-2021-1776 is an out-of-bounds write vulnerability in Apple's font processing that allows arbitrary code execution when processing malicious font f...

Apr 2, 2021
CVE-2021-1738
7.8

CVE-2021-1738 is an out-of-bounds write vulnerability in macOS image processing that could allow arbitrary code execution when processing a malicious ...

Apr 2, 2021
CVE-2021-1744
7.8

This vulnerability allows arbitrary code execution through malicious image processing. An attacker can craft a malicious image that triggers an out-of...

Apr 2, 2021
CVE-2020-9955
7.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write issue. It affects Apple dev...

Apr 2, 2021
CVE-2020-9967
7.8

CVE-2020-9967 is a kernel memory corruption vulnerability in Apple's XNU network stack that allows remote attackers to cause system crashes or corrupt...

Apr 2, 2021
CVE-2020-29611
7.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write memory corruption issue. It...

Apr 2, 2021
CVE-2020-29614
7.8

CVE-2020-29614 is a heap corruption vulnerability in Apple operating systems that allows attackers to execute arbitrary code by tricking users into op...

Apr 2, 2021
CVE-2020-29616
7.8

This memory corruption vulnerability in macOS image processing allows attackers to execute arbitrary code by tricking users into opening maliciously c...

Apr 2, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,359 CVEs classified as CWE-787, with 839 rated critical and 2,307 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free