CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,377)
This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write issue. It affects Apple dev...
Apr 2, 2021CVE-2020-9967 is a kernel memory corruption vulnerability in Apple's XNU network stack that allows remote attackers to cause system crashes or corrupt...
Apr 2, 2021This vulnerability allows arbitrary code execution by processing a maliciously crafted image due to an out-of-bounds write memory corruption issue. It...
Apr 2, 2021CVE-2020-29614 is a heap corruption vulnerability in Apple operating systems that allows attackers to execute arbitrary code by tricking users into op...
Apr 2, 2021This memory corruption vulnerability in macOS image processing allows attackers to execute arbitrary code by tricking users into opening maliciously c...
Apr 2, 2021This memory corruption vulnerability in Apple's font processing allows attackers to execute arbitrary code by tricking users into opening malicious fo...
Apr 2, 2021CVE-2020-27944 is a memory corruption vulnerability in Apple's font processing that allows arbitrary code execution when processing malicious font fil...
Apr 2, 2021This is a memory corruption vulnerability in macOS kernel that allows an application to execute arbitrary code with kernel privileges. It affects macO...
Apr 2, 2021CVE-2020-27897 is an out-of-bounds write vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. This affe...
Apr 2, 2021This is a memory corruption vulnerability in macOS kernel that allows an application to execute arbitrary code with kernel privileges. It affects macO...
Apr 2, 2021This memory corruption vulnerability in macOS allows malicious applications to execute arbitrary code with system privileges. It affects macOS Catalin...
Apr 2, 2021CVE-2020-27919 is an out-of-bounds write vulnerability in macOS image processing that could allow arbitrary code execution when processing a malicious...
Apr 2, 2021This vulnerability allows arbitrary code execution through malicious image processing. An attacker can craft a malicious image that triggers an out-of...
Apr 2, 2021CVE-2020-27931 is a memory corruption vulnerability in Apple's font processing that allows arbitrary code execution when processing malicious font fil...
Apr 2, 2021This CVE describes an out-of-bounds write vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affec...
Apr 2, 2021This vulnerability allows remote attackers to execute arbitrary code on Foxit PhantomPDF installations by tricking users into opening malicious PDF fi...
Mar 30, 2021FastStone Image Viewer version 7.5 and earlier contains a memory corruption vulnerability when processing malformed CUR cursor files. Attackers can ex...
Mar 18, 2021FastStone Image Viewer version 7.5 and earlier contains a memory corruption vulnerability when processing malformed CUR cursor files. Attackers can ex...
Mar 18, 2021This CVE describes a heap buffer overflow vulnerability in the Android sound trigger subsystem that allows local privilege escalation without user int...
Mar 10, 2021CVE-2021-28026 is a heap buffer overflow vulnerability in jpeg-xl v0.3.2 that allows arbitrary code execution or denial of service when decoding malic...
Mar 5, 2021CVE-2021-22683 is an out-of-bounds write vulnerability in Fatek FvDesigner software that allows arbitrary code execution when processing malicious pro...
Mar 3, 2021This vulnerability allows remote code execution through specially crafted image files processed by Microsoft Windows Codecs Library. Attackers can exp...
Feb 25, 2021CVE-2021-24083 is a remote code execution vulnerability in Windows Address Book that allows attackers to execute arbitrary code on affected systems. I...
Feb 25, 2021CVE-2021-1732 is a privilege escalation vulnerability in the Windows Win32k kernel driver. It allows a local attacker to gain SYSTEM-level privileges ...
Feb 25, 2021CVE-2021-21065 is an out-of-bounds write vulnerability in Adobe Bridge that allows arbitrary code execution when a user opens a malicious TTF file. It...
Feb 25, 2021This vulnerability is an out-of-bounds write in Intel Graphics Drivers that allows an authenticated local user to potentially escalate privileges. It ...
Feb 17, 2021CVE-2020-27860 is a remote code execution vulnerability in Foxit Reader that allows attackers to execute arbitrary code by tricking users into opening...
Feb 12, 2021CVE-2021-21052 is an out-of-bounds write vulnerability in Adobe Animate that allows arbitrary code execution when a user opens a malicious file. Attac...
Feb 11, 2021CVE-2021-21054 is an out-of-bounds write vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Atta...
Feb 11, 2021CVE-2021-21058 is a memory corruption vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF ...
Feb 11, 2021A memory corruption vulnerability in Adobe Acrobat Reader DC allows arbitrary code execution when parsing malicious PDF files. Attackers can exploit t...
Feb 11, 2021CVE-2021-21048 is a memory corruption vulnerability in Adobe Photoshop that allows arbitrary code execution when a user opens a specially crafted mali...
Feb 11, 2021CVE-2021-21044 is an out-of-bounds write vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when parsing malicious JPEG fil...
Feb 11, 2021A stack-based buffer overflow vulnerability in PrusaSlicer's OBJ file parser allows remote code execution when processing malicious 3D model files. Us...
Feb 10, 2021This CVE describes a memory corruption vulnerability in Android's Bluetooth stack where missing bounds checks in native functions could allow out-of-b...
Feb 10, 2021This vulnerability allows remote attackers to execute arbitrary code by exploiting a buffer overflow in Foxit Studio Photo's EZIX file handling. Attac...
Feb 9, 2021This vulnerability allows remote code execution through specially crafted TGA image files in Siemens JT2Go and Teamcenter Visualization software. Atta...
Feb 9, 2021This CVE describes an out-of-bounds write vulnerability in Trend Micro security products that allows a local attacker with low-privileged code executi...
Feb 4, 2021A heap-based buffer overflow vulnerability in SoftMaker Office 2021's PlanMaker allows attackers to execute arbitrary code by tricking users into open...
Feb 4, 2021This vulnerability is a heap-based buffer overflow in Libgcrypt's _gcry_md_block_write function when processing large count values during digest final...
Jan 29, 2021This vulnerability allows attackers to execute arbitrary code on affected systems by crafting malicious project files that trigger out-of-bounds write...
Jan 27, 2021This vulnerability in the autorand Rust crate allows memory corruption when uninitialized memory is dropped during a panic. It affects Rust applicatio...
Jan 26, 2021CVE-2020-35844 is an out-of-bounds write vulnerability in FastStone Image Viewer 7.5 that allows remote code execution when a user opens a specially c...
Jan 26, 2021CVE-2020-11185 is an out-of-bounds write vulnerability in Qualcomm WLAN drivers that allows attackers to execute arbitrary code or cause denial of ser...
Jan 21, 2021This vulnerability in Solid Edge allows attackers to execute arbitrary code by exploiting improper validation of PAR files. Users of Solid Edge SE2020...
Jan 12, 2021CVE-2021-1715 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code by tricking users into openin...
Jan 12, 2021Delta Electronics DOPSoft versions 4.0.8.21 and earlier contain an out-of-bounds write vulnerability when processing project files, allowing attackers...
Jan 11, 2021A buffer overflow vulnerability in K7AntiVirus Premium allows attackers to execute arbitrary code by sending specially crafted data. This affects user...
Jan 11, 2021This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of VLC media player by tricking users into openin...
Jan 8, 2021CVE-2020-35963 is an out-of-bounds write vulnerability in Fluent Bit's gzip compression function that could allow attackers to execute arbitrary code ...
Jan 3, 2021About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,377 CVEs classified as CWE-787, with 842 rated critical and 2,322 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free