CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,377
Total CVEs
842
Critical
2,322
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 404
2 Adobe 289
3 Apple 247
4 Linux 232
5 Debian 195
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 89
9 Samsung 78
10 Mozilla 78

All Out-of-bounds Write CVEs (3,377)

CVE-2020-1554
7.8

CVE-2020-1554 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with full user rights. ...

Aug 17, 2020
CVE-2020-1525
7.8

CVE-2020-1525 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with full user rights. ...

Aug 17, 2020
CVE-2020-1380
7.8

CVE-2020-1380 is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code by expl...

Aug 17, 2020
CVE-2020-0513
7.8

This vulnerability in Intel Graphics Drivers allows an authenticated local user to write data beyond allocated memory boundaries, potentially enabling...

Aug 13, 2020
CVE-2020-16213
7.8

This vulnerability in Advantech WebAccess HMI Designer allows attackers to execute arbitrary code by tricking users into opening malicious project fil...

Aug 6, 2020
CVE-2020-4549
7.8

This vulnerability in IBM i2 Analyst Notebook allows local attackers to execute arbitrary code through memory corruption. Attackers can exploit it by ...

Aug 3, 2020
CVE-2020-4551
7.8

This vulnerability in IBM i2 Analyst Notebook allows a local attacker to execute arbitrary code on the system by exploiting a memory corruption issue....

Aug 3, 2020
CVE-2020-4553
7.8

This vulnerability in IBM i2 Analyst Notebook allows a local attacker to execute arbitrary code through memory corruption. By tricking a user into ope...

Aug 3, 2020
CVE-2020-1457
7.8

This vulnerability allows remote code execution via specially crafted image files processed by the Microsoft Windows Codecs Library. Attackers can exp...

Jul 27, 2020
CVE-2020-15904
7.8

CVE-2020-15904 is a heap buffer overflow vulnerability in bsdiff4's patching routine that allows attackers to write beyond allocated memory bounds via...

Jul 22, 2020
CVE-2020-9674
7.8

CVE-2020-9674 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. This affect...

Jul 22, 2020
CVE-2020-9676
7.8

CVE-2020-9676 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. This affect...

Jul 22, 2020
CVE-2020-0226
7.8

This vulnerability allows local privilege escalation in Android's graphics server through an out-of-bounds write caused by type confusion. Attackers c...

Jul 17, 2020
CVE-2020-0120
7.8

This CVE describes a heap buffer overflow vulnerability in Android's camera subsystem that allows local privilege escalation. Attackers can exploit th...

Jul 17, 2020
CVE-2020-9646
7.8

CVE-2020-9646 is an out-of-bounds write vulnerability in Adobe Media Encoder that could allow attackers to execute arbitrary code on affected systems....

Jul 17, 2020
CVE-2020-9650
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Media Encoder that could allow attackers to execute arbitrary code on affected system...

Jul 17, 2020
CVE-2019-8066
7.8

This heap overflow vulnerability in Adobe Acrobat and Reader allows attackers to execute arbitrary code by exploiting memory corruption. Users running...

Jul 6, 2020
CVE-2020-9569
7.8

CVE-2020-9569 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. Users runni...

Jun 26, 2020
CVE-2020-9571
7.8

Adobe Illustrator versions 24.0.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...

Jun 26, 2020
CVE-2020-9573
7.8

A memory corruption vulnerability in Adobe Illustrator versions 24.0.2 and earlier allows attackers to execute arbitrary code by tricking users into o...

Jun 26, 2020
CVE-2020-9563
7.8

A heap overflow vulnerability in Adobe Bridge allows attackers to execute arbitrary code on affected systems. This affects users running Adobe Bridge ...

Jun 26, 2020
CVE-2020-9565
7.8

Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...

Jun 26, 2020
CVE-2020-9554
7.8

Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...

Jun 26, 2020
CVE-2020-9556
7.8

Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...

Jun 26, 2020
CVE-2020-9559
7.8

CVE-2020-9559 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. Users runni...

Jun 26, 2020
CVE-2020-9561
7.8

Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...

Jun 26, 2020
CVE-2020-9590
7.8

CVE-2020-9590 is a heap overflow vulnerability in Adobe DNG SDK versions 1.5 and earlier that allows attackers to execute arbitrary code by exploiting...

Jun 26, 2020
CVE-2020-9620
7.8

This CVE describes a heap overflow vulnerability in Adobe DNG SDK versions 1.5 and earlier, which could allow an attacker to execute arbitrary code by...

Jun 26, 2020
CVE-2020-9654
7.8

Adobe Premiere Pro versions 14.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affe...

Jun 25, 2020
CVE-2020-9656
7.8

Adobe Premiere Rush versions 1.5.12 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a...

Jun 25, 2020
CVE-2020-9658
7.8

Adobe Audition versions 13.0.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affect...

Jun 25, 2020
CVE-2020-9660
7.8

Adobe After Effects versions 17.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on aff...

Jun 25, 2020
CVE-2020-9662
7.8

Adobe After Effects versions 17.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on aff...

Jun 25, 2020
CVE-2020-9637
7.8

Adobe After Effects versions 17.1 and earlier contain a heap overflow vulnerability (CWE-787) that could allow attackers to execute arbitrary code on ...

Jun 25, 2020
CVE-2020-9639
7.8

This memory corruption vulnerability in Adobe Illustrator allows attackers to execute arbitrary code on affected systems. Users running Illustrator ve...

Jun 25, 2020
CVE-2020-9641
7.8

Adobe Illustrator versions 24.1.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...

Jun 25, 2020
CVE-2020-9594
7.8

This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat and Reader that could allow attackers to execute arbitrary code on affected s...

Jun 25, 2020
CVE-2020-9575
7.8

Adobe Illustrator versions 24.1.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...

Jun 25, 2020
CVE-2019-10597
7.8

This CVE-2019-10597 vulnerability in Qualcomm Snapdragon kernels allows attackers to write arbitrary memory due to missing user address validation. It...

Jun 22, 2020
CVE-2020-0234
7.8

This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the kernel's audio driver. Attackers can gai...

Jun 16, 2020
CVE-2020-0150
7.8

This CVE describes an out-of-bounds write vulnerability in Android's NFC stack that could allow local privilege escalation without user interaction. A...

Jun 11, 2020
CVE-2020-0155
7.8

This CVE describes a local privilege escalation vulnerability in Android's NFC controller hardware abstraction layer. An attacker with user-level acce...

Jun 11, 2020
CVE-2020-0986
7.8

This Windows kernel vulnerability allows attackers to gain elevated privileges by exploiting improper memory object handling. It affects Windows syste...

Jun 9, 2020
CVE-2020-9830
7.8

This is a memory corruption vulnerability in Apple's iOS, iPadOS, and macOS that allows an application to execute arbitrary code with kernel privilege...

Jun 9, 2020
CVE-2020-9834
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS syste...

Jun 9, 2020
CVE-2020-9822
7.8

This CVE describes a kernel privilege escalation vulnerability in macOS where a malicious application could exploit an out-of-bounds write to execute ...

Jun 9, 2020
CVE-2020-9813
7.8

This is a memory corruption vulnerability in Apple operating systems that allows a malicious application to execute arbitrary code with kernel privile...

Jun 9, 2020
CVE-2020-13428
7.8

A heap-based buffer overflow vulnerability in VLC media player's H.264 video processing allows remote attackers to crash the application or execute ar...

Jun 8, 2020
CVE-2020-13811
7.8

This vulnerability in Foxit Studio Photo allows attackers to execute arbitrary code by exploiting an out-of-bounds write vulnerability when processing...

Jun 4, 2020
CVE-2020-1054
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting a memory handling flaw in the Win32k kernel driver. ...

May 21, 2020

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,377 CVEs classified as CWE-787, with 842 rated critical and 2,322 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free