CWE-787 · 10,893 records
Out-of-bounds Write
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
99Now | CVE-2023-34048Weaponized | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Critical9.8 | KEV | 99.4% | Oct 25, 2023 |
98Now | CVE-2019-5544Weaponized | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Critical9.8 | KEV | 97.3% | Dec 6, 2019 |
97Now | CVE-2021-35211Weaponized | Serv-U Remote Memory Escape Vulnerabilitysolarwinds · serv-u · CWE-787 | Critical10.0 | KEV | 91.2% | Jul 14, 2021 |
96Now | CVE-2011-2462Weaponized | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x adobe · acrobat · CWE-787 | Critical9.8 | KEV | 88.5% | Dec 7, 2011 |
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
95Now | CVE-2021-31755Weaponized | An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN.tenda · ac11 firmware · CWE-787 | Critical9.8 | KEV | 86.9% | May 7, 2021 |
94Now | CVE-2018-0798Weaponized | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execumicrosoft · office · CWE-787 | High8.8 | KEV | 95.1% | Jan 9, 2018 |
94Now | CVE-2025-9242Weaponized | WatchGuard Firebox iked Out of Bounds Write Vulnerabilitywatchguard · fireware · CWE-787 | Critical9.3 | KEV | 91.3% | Sep 17, 2025 |
94Now | CVE-2024-21762Weaponized | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2fortinet · fortiproxy · CWE-787 | Critical9.8 | KEV | 83.4% | Feb 9, 2024 |
94Now | CVE-2020-14871Weaponized | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).oracle · solaris · CWE-787 | Critical10.0 | KEV | 80.2% | Oct 21, 2020 |
93Now | CVE-2013-3346Weaponized | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a adobe · acrobat · CWE-787 | Critical9.8 | KEV | 78.9% | Aug 30, 2013 |
91Now | CVE-2008-2992Weaponized | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file tadobe · acrobat · CWE-787 | High7.8 | KEV | 98.5% | Nov 4, 2008 |
91Now | CVE-2015-3043Weaponized | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attadobe · flash player · CWE-787 | Critical9.8 | KEV | 73.9% | Apr 14, 2015 |
91Now | CVE-2010-4344Weaponized | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Critical9.8 | KEV | 71.7% | Dec 14, 2010 |
90Now | CVE-2015-1641Weaponized | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, microsoft · office · CWE-787 | High7.8 | KEV | 96.7% | Apr 14, 2015 |
90Now | CVE-2012-1889Weaponized | Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitramicrosoft · xml core services · CWE-787 | High8.8 | KEV | 83.5% | Jun 13, 2012 |
90Now | CVE-2009-3953Weaponized | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remotadobe · acrobat · CWE-787 | High8.8 | KEV | 83.2% | Jan 13, 2010 |
90Now | CVE-2016-7200Weaponized | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memmicrosoft · edge · CWE-787 | High8.8 | KEV | 82.8% | Nov 10, 2016 |
89Now | CVE-2021-4034Weaponized | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | High7.8 | KEV | 94.3% | Jan 28, 2022 |
89Now | CVE-2018-0802Weaponized | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executmicrosoft · office · CWE-787 | High7.8 | KEV | 93.3% | Jan 9, 2018 |
89Now | CVE-2012-0754Weaponized | Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.xadobe · flash player · CWE-787 | High8.1 | KEV | 91.2% | Feb 16, 2012 |
88Now | CVE-2016-0189Weaponized | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remomicrosoft · jscript · CWE-787 | High7.5 | KEV | 94.1% | May 10, 2016 |
88Now | CVE-2010-3333Weaponized | Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office microsoft · office · CWE-787 | High7.8 | KEV | 89.5% | Nov 9, 2010 |
87Now | CVE-2013-0640Weaponized | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cadobe · acrobat · CWE-787 | High7.8 | KEV | 86.9% | Feb 13, 2013 |
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2023-3404899Now
VMware vCenter Server Out-of-Bounds Write Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 99%vmware · vcenter serverOct 25, 2023
- CVE-2019-554498Now
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%openslp · openslpDec 6, 2019
- CVE-2021-3521197Now
Serv-U Remote Memory Escape Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 91%solarwinds · serv-uJul 14, 2021
- CVE-2011-246296Now
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x
CriticalCVSS 9.8KEVWeaponizedEPSS 89%adobe · acrobatDec 7, 2011
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023
- CVE-2021-3175595Now
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN.
CriticalCVSS 9.8KEVWeaponizedEPSS 87%tenda · ac11 firmwareMay 7, 2021
- CVE-2018-079894Now
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execu
HighCVSS 8.8KEVWeaponizedEPSS 95%microsoft · officeJan 9, 2018
- CVE-2025-924294Now
WatchGuard Firebox iked Out of Bounds Write Vulnerability
CriticalCVSS 9.3KEVWeaponizedEPSS 91%watchguard · firewareSep 17, 2025
- CVE-2024-2176294Now
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2
CriticalCVSS 9.8KEVWeaponizedEPSS 83%fortinet · fortiproxyFeb 9, 2024
- CVE-2020-1487194Now
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).
CriticalCVSS 10.0KEVWeaponizedEPSS 80%oracle · solarisOct 21, 2020
- CVE-2013-334693Now
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a
CriticalCVSS 9.8KEVWeaponizedEPSS 79%adobe · acrobatAug 30, 2013
- CVE-2008-299291Now
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file t
HighCVSS 7.8KEVWeaponizedEPSS 98%adobe · acrobatNov 4, 2008
- CVE-2015-304391Now
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows att
CriticalCVSS 9.8KEVWeaponizedEPSS 74%adobe · flash playerApr 14, 2015
- CVE-2010-434491Now
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
CriticalCVSS 9.8KEVWeaponizedEPSS 72%exim · eximDec 14, 2010
- CVE-2015-164190Now
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3,
HighCVSS 7.8KEVWeaponizedEPSS 97%microsoft · officeApr 14, 2015
- CVE-2012-188990Now
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitra
HighCVSS 8.8KEVWeaponizedEPSS 84%microsoft · xml core servicesJun 13, 2012
- CVE-2009-395390Now
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remot
HighCVSS 8.8KEVWeaponizedEPSS 83%adobe · acrobatJan 13, 2010
- CVE-2016-720090Now
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem
HighCVSS 8.8KEVWeaponizedEPSS 83%microsoft · edgeNov 10, 2016
- CVE-2021-403489Now
A local privilege escalation vulnerability was found on polkit's pkexec utility.
HighCVSS 7.8KEVWeaponizedEPSS 94%polkit project · polkitJan 28, 2022
- CVE-2018-080289Now
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execut
HighCVSS 7.8KEVWeaponizedEPSS 93%microsoft · officeJan 9, 2018
- CVE-2012-075489Now
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x
HighCVSS 8.1KEVWeaponizedEPSS 91%adobe · flash playerFeb 16, 2012
- CVE-2016-018988Now
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remo
HighCVSS 7.5KEVWeaponizedEPSS 94%microsoft · jscriptMay 10, 2016
- CVE-2010-333388Now
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office
HighCVSS 7.8KEVWeaponizedEPSS 89%microsoft · officeNov 9, 2010
- CVE-2013-064087Now
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or c
HighCVSS 7.8KEVWeaponizedEPSS 87%adobe · acrobatFeb 13, 2013