CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,377
Total CVEs
842
Critical
2,322
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 404
2 Adobe 288
3 Apple 247
4 Linux 232
5 Debian 195
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 89
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,377)

CVE-2020-9955
7.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write issue. It affects Apple dev...

Apr 2, 2021
CVE-2020-9967
7.8

CVE-2020-9967 is a kernel memory corruption vulnerability in Apple's XNU network stack that allows remote attackers to cause system crashes or corrupt...

Apr 2, 2021
CVE-2020-29611
7.8

This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write memory corruption issue. It...

Apr 2, 2021
CVE-2020-29614
7.8

CVE-2020-29614 is a heap corruption vulnerability in Apple operating systems that allows attackers to execute arbitrary code by tricking users into op...

Apr 2, 2021
CVE-2020-29616
7.8

This memory corruption vulnerability in macOS image processing allows attackers to execute arbitrary code by tricking users into opening maliciously c...

Apr 2, 2021
CVE-2020-29624
7.8

This memory corruption vulnerability in Apple's font processing allows attackers to execute arbitrary code by tricking users into opening malicious fo...

Apr 2, 2021
CVE-2020-27944
7.8

CVE-2020-27944 is a memory corruption vulnerability in Apple's font processing that allows arbitrary code execution when processing malicious font fil...

Apr 2, 2021
CVE-2020-27947
7.8

This is a memory corruption vulnerability in macOS kernel that allows an application to execute arbitrary code with kernel privileges. It affects macO...

Apr 2, 2021
CVE-2020-27897
7.8

CVE-2020-27897 is an out-of-bounds write vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. This affe...

Apr 2, 2021
CVE-2020-27907
7.8

This is a memory corruption vulnerability in macOS kernel that allows an application to execute arbitrary code with kernel privileges. It affects macO...

Apr 2, 2021
CVE-2020-27914
7.8

This memory corruption vulnerability in macOS allows malicious applications to execute arbitrary code with system privileges. It affects macOS Catalin...

Apr 2, 2021
CVE-2020-27919
7.8

CVE-2020-27919 is an out-of-bounds write vulnerability in macOS image processing that could allow arbitrary code execution when processing a malicious...

Apr 2, 2021
CVE-2020-27923
7.8

This vulnerability allows arbitrary code execution through malicious image processing. An attacker can craft a malicious image that triggers an out-of...

Apr 2, 2021
CVE-2020-27931
7.8

CVE-2020-27931 is a memory corruption vulnerability in Apple's font processing that allows arbitrary code execution when processing malicious font fil...

Apr 2, 2021
CVE-2020-10015
7.8

This CVE describes an out-of-bounds write vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affec...

Apr 2, 2021
CVE-2021-27269
7.8

This vulnerability allows remote attackers to execute arbitrary code on Foxit PhantomPDF installations by tricking users into opening malicious PDF fi...

Mar 30, 2021
CVE-2021-26234
7.8

FastStone Image Viewer version 7.5 and earlier contains a memory corruption vulnerability when processing malformed CUR cursor files. Attackers can ex...

Mar 18, 2021
CVE-2021-26237
7.8

FastStone Image Viewer version 7.5 and earlier contains a memory corruption vulnerability when processing malformed CUR cursor files. Attackers can ex...

Mar 18, 2021
CVE-2021-0464
7.8

This CVE describes a heap buffer overflow vulnerability in the Android sound trigger subsystem that allows local privilege escalation without user int...

Mar 10, 2021
CVE-2021-28026
7.8

CVE-2021-28026 is a heap buffer overflow vulnerability in jpeg-xl v0.3.2 that allows arbitrary code execution or denial of service when decoding malic...

Mar 5, 2021
CVE-2021-22683
7.8

CVE-2021-22683 is an out-of-bounds write vulnerability in Fatek FvDesigner software that allows arbitrary code execution when processing malicious pro...

Mar 3, 2021
CVE-2021-24081
7.8

This vulnerability allows remote code execution through specially crafted image files processed by Microsoft Windows Codecs Library. Attackers can exp...

Feb 25, 2021
CVE-2021-24083
7.8

CVE-2021-24083 is a remote code execution vulnerability in Windows Address Book that allows attackers to execute arbitrary code on affected systems. I...

Feb 25, 2021
CVE-2021-1732
7.8

CVE-2021-1732 is a privilege escalation vulnerability in the Windows Win32k kernel driver. It allows a local attacker to gain SYSTEM-level privileges ...

Feb 25, 2021
CVE-2021-21065
7.8

CVE-2021-21065 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious TTF file. It...

Feb 25, 2021
CVE-2020-24462
7.8

This vulnerability is an out-of-bounds write in Intel Graphics Drivers that allows an authenticated local user to potentially escalate privileges. It ...

Feb 17, 2021
CVE-2020-27860
7.8

CVE-2020-27860 is a remote code execution vulnerability in Foxit Reader that allows attackers to execute arbitrary code by tricking users into opening...

Feb 12, 2021
CVE-2021-21052
7.8

CVE-2021-21052 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. Attac...

Feb 11, 2021
CVE-2021-21054
7.8

CVE-2021-21054 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Atta...

Feb 11, 2021
CVE-2021-21058
7.8

CVE-2021-21058 is a memory corruption vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF ...

Feb 11, 2021
CVE-2021-21062
7.8

A memory corruption vulnerability in Adobe Acrobat Reader DC allows arbitrary code execution when parsing malicious PDF files. Attackers can exploit t...

Feb 11, 2021
CVE-2021-21048
7.8

CVE-2021-21048 is a memory corruption vulnerability in Adobe Photoshop that allows arbitrary code execution when a user opens a specially crafted mali...

Feb 11, 2021
CVE-2021-21044
7.8

CVE-2021-21044 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when parsing malicious JPEG fil...

Feb 11, 2021
CVE-2020-28596
7.8

A stack-based buffer overflow vulnerability in PrusaSlicer's OBJ file parser allows remote code execution when processing malicious 3D model files. Us...

Feb 10, 2021
CVE-2021-0329
7.8

This CVE describes a memory corruption vulnerability in Android's Bluetooth stack where missing bounds checks in native functions could allow out-of-b...

Feb 10, 2021
CVE-2020-17418
7.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a buffer overflow in Foxit Studio Photo's EZIX file handling. Attac...

Feb 9, 2021
CVE-2020-27005
7.8

This vulnerability allows remote code execution through specially crafted TGA image files in Siemens JT2Go and Teamcenter Visualization software. Atta...

Feb 9, 2021
CVE-2021-25249
7.8

This CVE describes an out-of-bounds write vulnerability in Trend Micro security products that allows a local attacker with low-privileged code executi...

Feb 4, 2021
CVE-2020-13580
7.8

A heap-based buffer overflow vulnerability in SoftMaker Office 2021's PlanMaker allows attackers to execute arbitrary code by tricking users into open...

Feb 4, 2021
CVE-2021-3345
7.8

This vulnerability is a heap-based buffer overflow in Libgcrypt's _gcry_md_block_write function when processing large count values during digest final...

Jan 29, 2021
CVE-2021-22653
7.8

This vulnerability allows attackers to execute arbitrary code on affected systems by crafting malicious project files that trigger out-of-bounds write...

Jan 27, 2021
CVE-2020-36210
7.8

This vulnerability in the autorand Rust crate allows memory corruption when uninitialized memory is dropped during a panic. It affects Rust applicatio...

Jan 26, 2021
CVE-2020-35844
7.8

CVE-2020-35844 is an out-of-bounds write vulnerability in FastStone Image Viewer 7.5 that allows remote code execution when a user opens a specially c...

Jan 26, 2021
CVE-2020-11185
7.8

CVE-2020-11185 is an out-of-bounds write vulnerability in Qualcomm WLAN drivers that allows attackers to execute arbitrary code or cause denial of ser...

Jan 21, 2021
CVE-2020-28382
7.8

This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting improper validation of PAR files. Users of Solid Edge SE2020...

Jan 12, 2021
CVE-2021-1715
7.8

CVE-2021-1715 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code by tricking users into openin...

Jan 12, 2021
CVE-2020-27275
7.8

Delta Electronics DOPSoft versions 4.0.8.21 and earlier contain an out-of-bounds write vulnerability when processing project files, allowing attackers...

Jan 11, 2021
CVE-2018-11009
7.8

A buffer overflow vulnerability in K7AntiVirus Premium allows attackers to execute arbitrary code by sending specially crafted data. This affects user...

Jan 11, 2021
CVE-2020-26664
7.8

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of VLC media player by tricking users into openin...

Jan 8, 2021
CVE-2020-35963
7.8

CVE-2020-35963 is an out-of-bounds write vulnerability in Fluent Bit's gzip compression function that could allow attackers to execute arbitrary code ...

Jan 3, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,377 CVEs classified as CWE-787, with 842 rated critical and 2,322 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free