CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (3,377)
CVE-2020-1554 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with full user rights. ...
Aug 17, 2020CVE-2020-1525 is a memory corruption vulnerability in Windows Media Foundation that allows attackers to execute arbitrary code with full user rights. ...
Aug 17, 2020CVE-2020-1380 is a remote code execution vulnerability in Internet Explorer's scripting engine that allows attackers to execute arbitrary code by expl...
Aug 17, 2020This vulnerability in Intel Graphics Drivers allows an authenticated local user to write data beyond allocated memory boundaries, potentially enabling...
Aug 13, 2020This vulnerability in Advantech WebAccess HMI Designer allows attackers to execute arbitrary code by tricking users into opening malicious project fil...
Aug 6, 2020This vulnerability in IBM i2 Analyst Notebook allows local attackers to execute arbitrary code through memory corruption. Attackers can exploit it by ...
Aug 3, 2020This vulnerability in IBM i2 Analyst Notebook allows a local attacker to execute arbitrary code on the system by exploiting a memory corruption issue....
Aug 3, 2020This vulnerability in IBM i2 Analyst Notebook allows a local attacker to execute arbitrary code through memory corruption. By tricking a user into ope...
Aug 3, 2020This vulnerability allows remote code execution via specially crafted image files processed by the Microsoft Windows Codecs Library. Attackers can exp...
Jul 27, 2020CVE-2020-15904 is a heap buffer overflow vulnerability in bsdiff4's patching routine that allows attackers to write beyond allocated memory bounds via...
Jul 22, 2020CVE-2020-9674 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. This affect...
Jul 22, 2020CVE-2020-9676 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. This affect...
Jul 22, 2020This vulnerability allows local privilege escalation in Android's graphics server through an out-of-bounds write caused by type confusion. Attackers c...
Jul 17, 2020This CVE describes a heap buffer overflow vulnerability in Android's camera subsystem that allows local privilege escalation. Attackers can exploit th...
Jul 17, 2020CVE-2020-9646 is an out-of-bounds write vulnerability in Adobe Media Encoder that could allow attackers to execute arbitrary code on affected systems....
Jul 17, 2020This CVE describes an out-of-bounds write vulnerability in Adobe Media Encoder that could allow attackers to execute arbitrary code on affected system...
Jul 17, 2020This heap overflow vulnerability in Adobe Acrobat and Reader allows attackers to execute arbitrary code by exploiting memory corruption. Users running...
Jul 6, 2020CVE-2020-9569 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. Users runni...
Jun 26, 2020Adobe Illustrator versions 24.0.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...
Jun 26, 2020A memory corruption vulnerability in Adobe Illustrator versions 24.0.2 and earlier allows attackers to execute arbitrary code by tricking users into o...
Jun 26, 2020A heap overflow vulnerability in Adobe Bridge allows attackers to execute arbitrary code on affected systems. This affects users running Adobe Bridge ...
Jun 26, 2020Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...
Jun 26, 2020Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...
Jun 26, 2020Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...
Jun 26, 2020CVE-2020-9559 is an out-of-bounds write vulnerability in Adobe Bridge that allows attackers to execute arbitrary code on affected systems. Users runni...
Jun 26, 2020Adobe Bridge versions 10.0.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affected...
Jun 26, 2020CVE-2020-9590 is a heap overflow vulnerability in Adobe DNG SDK versions 1.5 and earlier that allows attackers to execute arbitrary code by exploiting...
Jun 26, 2020This CVE describes a heap overflow vulnerability in Adobe DNG SDK versions 1.5 and earlier, which could allow an attacker to execute arbitrary code by...
Jun 26, 2020Adobe Premiere Pro versions 14.2 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affe...
Jun 25, 2020Adobe Premiere Rush versions 1.5.12 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a...
Jun 25, 2020Adobe Audition versions 13.0.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on affect...
Jun 25, 2020Adobe After Effects versions 17.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on aff...
Jun 25, 2020Adobe After Effects versions 17.1 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on aff...
Jun 25, 2020Adobe After Effects versions 17.1 and earlier contain a heap overflow vulnerability (CWE-787) that could allow attackers to execute arbitrary code on ...
Jun 25, 2020This memory corruption vulnerability in Adobe Illustrator allows attackers to execute arbitrary code on affected systems. Users running Illustrator ve...
Jun 25, 2020Adobe Illustrator versions 24.1.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...
Jun 25, 2020This CVE describes an out-of-bounds write vulnerability in Adobe Acrobat and Reader that could allow attackers to execute arbitrary code on affected s...
Jun 25, 2020Adobe Illustrator versions 24.1.2 and earlier contain a memory corruption vulnerability that could allow attackers to execute arbitrary code on affect...
Jun 25, 2020This CVE-2019-10597 vulnerability in Qualcomm Snapdragon kernels allows attackers to write arbitrary memory due to missing user address validation. It...
Jun 22, 2020This vulnerability allows local privilege escalation on Android devices through an out-of-bounds write in the kernel's audio driver. Attackers can gai...
Jun 16, 2020This CVE describes an out-of-bounds write vulnerability in Android's NFC stack that could allow local privilege escalation without user interaction. A...
Jun 11, 2020This CVE describes a local privilege escalation vulnerability in Android's NFC controller hardware abstraction layer. An attacker with user-level acce...
Jun 11, 2020This Windows kernel vulnerability allows attackers to gain elevated privileges by exploiting improper memory object handling. It affects Windows syste...
Jun 9, 2020This is a memory corruption vulnerability in Apple's iOS, iPadOS, and macOS that allows an application to execute arbitrary code with kernel privilege...
Jun 9, 2020This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects macOS syste...
Jun 9, 2020This CVE describes a kernel privilege escalation vulnerability in macOS where a malicious application could exploit an out-of-bounds write to execute ...
Jun 9, 2020This is a memory corruption vulnerability in Apple operating systems that allows a malicious application to execute arbitrary code with kernel privile...
Jun 9, 2020A heap-based buffer overflow vulnerability in VLC media player's H.264 video processing allows remote attackers to crash the application or execute ar...
Jun 8, 2020This vulnerability in Foxit Studio Photo allows attackers to execute arbitrary code by exploiting an out-of-bounds write vulnerability when processing...
Jun 4, 2020This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting a memory handling flaw in the Win32k kernel driver. ...
May 21, 2020About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 3,377 CVEs classified as CWE-787, with 842 rated critical and 2,322 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free