VYPR

CWE-123

Write-what-where Condition

BaseDraftLikelihood: High

Description

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (57)

page 1 of 3
  • CVE-2025-22225HigKEVMar 4, 2025
    risk 0.71cvss 8.2epss 0.01

    VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

  • CVE-2025-69809CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet.

  • CVE-2022-38143CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to…

  • CVE-2021-38449CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of the affected product.

  • CVE-2014-5435CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.03

    An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remote code execution or denial of service. Honeywell strongly encourages and…

  • CVE-2015-8271CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.06

    The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.

  • CVE-2026-43284HigMay 8, 2026
    risk 0.61cvss 8.8epss 0.93

    In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths…

  • CVE-2024-42479CriAug 12, 2024
    risk 0.58cvss 10.0epss 0.03

    llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561.

  • CVE-2025-9900HigSep 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into…

  • CVE-2022-41757HigNov 8, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to obtain write access to read-only memory, or obtain access to already freed memory. This affects Valhall r29p0 through r38p1 before r38p2, and r39p0…

  • CVE-2020-7560HigDec 11, 2020
    risk 0.56cvss 8.6epss 0.01

    A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious…

  • CVE-2024-44067HigAug 19, 2024
    risk 0.55cvss 8.4epss 0.00

    The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.

  • CVE-2026-43500HigMay 11, 2026
    risk 0.54cvss 7.8epss 0.93

    In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one…

  • CVE-2025-33045HigSep 9, 2025
    risk 0.53cvss 8.2epss 0.00

    APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through local access. The successful exploitation of these vulnerabilities can lead to information…

  • CVE-2024-36877HigAug 12, 2024
    risk 0.53cvss 8.2epss 0.01

    Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI…

  • CVE-2024-2607HigMar 19, 2024
    risk 0.53cvss 8.1epss 0.01

    Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2022-35408HigSep 22, 2022
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the function pointers in the…

  • CVE-2022-40262HigSep 20, 2022
    risk 0.53cvss 8.2epss 0.00

    A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing…

  • CVE-2020-2001HigMay 13, 2020
    risk 0.53cvss 8.1epss 0.01

    An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges. This…

  • CVE-2026-30121CriJun 15, 2026
    risk 0.52cvss 9.1epss 0.00

    remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.