CWE-787: Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

3,377
Total CVEs
842
Critical
2,322
High
8.3
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
99
2025
520
2024
596
2023
545
2022
364

Top Affected Vendors

1 Google 404
2 Adobe 290
3 Apple 247
4 Linux 232
5 Debian 195
6 Tenda 189
7 Fedoraproject 136
8 Microsoft 89
9 Mozilla 78
10 Samsung 78

All Out-of-bounds Write CVEs (3,377)

CVE-2019-8253
7.8

This memory corruption vulnerability in Adobe Photoshop CC allows attackers to execute arbitrary code on affected systems. Users running Photoshop CC ...

Dec 19, 2019
CVE-2019-8807
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with system privileges. It affects macOS syste...

Dec 18, 2019
CVE-2019-8795
7.8

This memory corruption vulnerability in Apple iOS/iPadOS/tvOS allows malicious applications to execute arbitrary code with system privileges. It affec...

Dec 18, 2019
CVE-2019-8800
7.8

CVE-2019-8800 is a memory corruption vulnerability in Xcode that allows arbitrary code execution when processing malicious files. This affects develop...

Dec 18, 2019
CVE-2019-8786
7.8

CVE-2019-8786 is a memory corruption vulnerability in Apple operating systems that allows applications to execute arbitrary code with kernel privilege...

Dec 18, 2019
CVE-2019-8784
7.8

CVE-2019-8784 is a memory corruption vulnerability in multiple Apple products that allows an application to execute arbitrary code with system privile...

Dec 18, 2019
CVE-2019-8758
7.8

This is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with system privileges. It affects macOS syste...

Dec 18, 2019
CVE-2019-8747
7.8

CVE-2019-8747 is a memory corruption vulnerability in Apple watchOS that allows an application to execute arbitrary code with kernel privileges. This ...

Dec 18, 2019
CVE-2019-8738
7.8

CVE-2019-8738 is a memory corruption vulnerability in Xcode that allows arbitrary code execution when processing malicious files. This affects develop...

Dec 18, 2019
CVE-2019-8616
7.8

CVE-2019-8616 is a memory corruption vulnerability in macOS that allows an application to execute arbitrary code with system privileges. This affects ...

Dec 18, 2019
CVE-2019-8602
7.8

CVE-2019-8602 is a memory corruption vulnerability in SQLite that allows malicious applications to execute arbitrary code with elevated privileges. It...

Dec 18, 2019
CVE-2019-8593
7.8

CVE-2019-8593 is a memory corruption vulnerability in Apple iOS, tvOS, and watchOS that allows an application to execute arbitrary code with system pr...

Dec 18, 2019
CVE-2019-7287
7.8

CVE-2019-7287 is a memory corruption vulnerability in iOS that allows malicious applications to execute arbitrary code with kernel privileges. This af...

Dec 18, 2019
CVE-2019-10480
7.8

This vulnerability allows an attacker to write data outside the intended memory buffer in the WMI firmware event handler due to insufficient validatio...

Dec 18, 2019
CVE-2019-19814
7.8

This vulnerability allows an attacker to cause a kernel memory corruption (slab-out-of-bounds write) by mounting a specially crafted f2fs filesystem i...

Dec 17, 2019
CVE-2019-19795
7.8

CVE-2019-19795 is a heap-based buffer overflow vulnerability in the canonpath function of samurai build system version 0.7. Attackers can exploit this...

Dec 13, 2019
CVE-2019-19785
7.8

CVE-2019-19785 is a stack-based buffer overflow vulnerability in ATasm 1.06's to_comma() function in asm.c that can be triggered by processing a malic...

Dec 13, 2019
CVE-2019-19787
7.8

CVE-2019-19787 is a stack-based buffer overflow vulnerability in ATasm 1.06 that occurs when processing malicious .m65 files. Attackers can exploit th...

Dec 13, 2019
CVE-2019-2319
7.8

This vulnerability allows the HLOS (High-Level Operating System) to corrupt CPZ (Content Protection Zone) page table memory for S1 managed virtual mac...

Dec 12, 2019
CVE-2015-7892
7.8

This vulnerability is a stack-based buffer overflow in Samsung's m2m1shot kernel driver framework. It allows local users to execute arbitrary code wit...

Dec 9, 2019
CVE-2019-2223
7.8

This vulnerability allows remote code execution on Android devices through a missing bounds check in the ihevcd_ref_list function. Attackers can explo...

Dec 6, 2019
CVE-2019-19378
7.8

This vulnerability in the Linux kernel allows an attacker to cause a slab-out-of-bounds write by mounting a specially crafted btrfs filesystem image. ...

Nov 29, 2019
CVE-2019-13706
7.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's PDFium PDF rendering engine, potentially leading to hea...

Nov 25, 2019
CVE-2014-5439
7.8

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of Sniffit network sniffer. By crafting a malicio...

Nov 19, 2019
CVE-2019-11112
7.8

This vulnerability allows an authenticated user to exploit memory corruption in Intel Graphics Kernel Mode Drivers to potentially escalate privileges ...

Nov 14, 2019
CVE-2019-2201
7.8

This vulnerability allows remote code execution through an out-of-bounds write in Android's JPEG processing library. Attackers can exploit this by tri...

Nov 13, 2019
CVE-2019-2203
7.8

CVE-2019-2203 is a heap buffer overflow vulnerability in Android's CryptoPlugin that allows local privilege escalation without user interaction. Attac...

Nov 13, 2019
CVE-2019-1396
7.8

This Windows privilege escalation vulnerability allows attackers to gain SYSTEM-level privileges by exploiting improper memory handling in the Win32k ...

Nov 12, 2019
CVE-2019-1394
7.8

This Windows privilege escalation vulnerability allows attackers to gain SYSTEM-level privileges by exploiting improper memory handling in the Win32k ...

Nov 12, 2019
CVE-2019-5084
7.8

A heap out-of-bounds write vulnerability in LEADTOOLS 20's TIF parsing functionality allows attackers to execute arbitrary code by crafting a maliciou...

Nov 6, 2019
CVE-2019-5088
7.8

This vulnerability allows remote code execution through a specially crafted BMP file in Investintech Able2Extract Professional. Attackers can exploit ...

Nov 5, 2019
CVE-2019-17624
7.8

CVE-2019-17624 is a stack-based buffer overflow vulnerability in X.Org X Server's XQueryKeymap function. Attackers can trigger this by sending excessi...

Oct 16, 2019
CVE-2019-14570
7.8

This vulnerability involves memory corruption in Intel NUC system firmware that allows a privileged user with local access to potentially escalate pri...

Oct 11, 2019
CVE-2019-17262
7.8

CVE-2019-17262 is an out-of-bounds write vulnerability in XnView Classic 2.49.1 that allows attackers to execute arbitrary code by exploiting a memory...

Oct 8, 2019
CVE-2019-17249
7.8

CVE-2019-17249 is a memory corruption vulnerability in IrfanView's WSQ file parser that allows an attacker to execute arbitrary code. When a user open...

Oct 8, 2019
CVE-2019-17251
7.8

CVE-2019-17251 is a memory corruption vulnerability in IrfanView's plugin handling that allows attackers to execute arbitrary code. This affects users...

Oct 8, 2019
CVE-2019-17253
7.8

CVE-2019-17253 is a memory corruption vulnerability in IrfanView's JPEG-LS decoder that allows attackers to execute arbitrary code or cause denial of ...

Oct 8, 2019
CVE-2019-17255
7.8

CVE-2019-17255 is a memory corruption vulnerability in IrfanView's EXR file parser that allows attackers to execute arbitrary code by tricking users i...

Oct 8, 2019
CVE-2019-17258
7.8

CVE-2019-17258 is a memory corruption vulnerability in IrfanView's JPEG-LS decoder that allows an attacker to control a write address through data fro...

Oct 8, 2019
CVE-2019-17241
7.8

CVE-2019-17241 is a memory corruption vulnerability in IrfanView's WSQ file parser that allows attackers to execute arbitrary code by tricking users i...

Oct 8, 2019
CVE-2019-17245
7.8

CVE-2019-17245 is a memory corruption vulnerability in IrfanView's WSQ file parser that allows attackers to execute arbitrary code or cause denial of ...

Oct 8, 2019
CVE-2019-1199
7.8

A memory corruption vulnerability in Microsoft Outlook allows remote code execution when users open specially crafted malicious files. Attackers can e...

Aug 14, 2019
CVE-2026-25506
7.7

A buffer overflow vulnerability in MUNGE authentication daemon (munged) versions 0.5 to 0.5.17 allows local attackers to leak cryptographic key materi...

Feb 10, 2026
CVE-2023-34402
7.7

This vulnerability in Mercedes-Benz NTG6 head units allows attackers to write arbitrary files with speech service privileges by exploiting insufficien...

Feb 13, 2025
CVE-2024-29743
7.7

CVE-2024-29743 is an out-of-bounds write vulnerability in the tmu_set_temp_lut function of tmu.c in Android's Pixel kernel. This allows local attacker...

Apr 5, 2024
CVE-2024-27211
7.7

This vulnerability allows local privilege escalation on affected Android Pixel devices through an out-of-bounds write in the ATI driver. Attackers can...

Mar 11, 2024
CVE-2023-35871
7.7

CVE-2023-35871 is a memory corruption vulnerability in SAP Web Dispatcher and related components that allows unauthenticated attackers to cause logica...

Jul 11, 2023
CVE-2021-43814
7.7

CVE-2021-43814 is a heap-based out-of-bounds write vulnerability in Rizin's parse_die() function when processing AMD64 ELF binaries with DWARF debug i...

Dec 13, 2021
CVE-2021-34375
7.7

CVE-2021-34375 is a stack cookie randomization vulnerability in NVIDIA Trusty trusted applications (TAs) that could allow stack-based buffer overflows...

Jun 30, 2021
CVE-2021-34379
7.7

This vulnerability in NVIDIA's Trusty HDCP service allows attackers to exploit missing bounds checking in command 10, potentially leading to memory co...

Jun 30, 2021

About Out-of-bounds Write (CWE-787)

The product writes data past the end, or before the beginning, of the intended buffer.

Our database tracks 3,377 CVEs classified as CWE-787, with 842 rated critical and 2,322 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.3.

External reference: View CWE-787 on MITRE CWE →

Monitor Out-of-bounds Write Vulnerabilities

Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.

Start Monitoring Free