VYPR

CWE-123

Write-what-where Condition

BaseDraftLikelihood: High

Description

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (64)

page 3 of 4
  • CVE-2022-40246HigSep 20, 2022
    risk 0.47cvss 7.2epss 0.00

    A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mode) and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from…

  • CVE-2026-46323HigJun 9, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When…

  • CVE-2024-20119MedNov 4, 2024
    risk 0.44cvss 6.7epss 0.00

    In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: MSV-1620.

  • CVE-2024-20118MedNov 4, 2024
    risk 0.44cvss 6.7epss 0.00

    In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062392; Issue ID: MSV-1621.

  • CVE-2021-1520MedMay 6, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the internal message processing of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, local attacker to run arbitrary commands with root privileges on the underlying operating system (OS). This vulnerability…

  • CVE-2018-15376MedOct 5, 2018
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The…

  • CVE-2018-15375MedOct 5, 2018
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The…

  • CVE-2026-48977HigSep 17, 2026
    risk 0.43cvss —epss 0.00

    OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce…

  • CVE-2025-64324HigNov 18, 2025
    risk 0.43cvss 7.7epss 0.00

    KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more…

  • CVE-2024-20141MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…

  • CVE-2022-37904MedDec 12, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

  • CVE-2021-38441MedMay 5, 2022
    risk 0.43cvss 6.6epss 0.02

    Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.

  • CVE-2025-55298HigAug 26, 2025
    risk 0.42cvss 7.5epss 0.04

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to…

  • CVE-2022-1523MedOct 19, 2022
    risk 0.40cvss 6.1epss 0.01

    Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an attacker to overwrite program memory to manipulate the flow of information.

  • CVE-2026-20469MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868;…

  • CVE-2024-47438MedNov 12, 2024
    risk 0.36cvss 5.5epss 0.00

    Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacker to write a controlled value at a controlled memory location, which could result in the disclosure…

  • CVE-2025-14857MedApr 7, 2026
    risk 0.35cvss —epss 0.00

    An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical…

  • CVE-2021-1390MedMar 24, 2021
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege…

  • CVE-2025-29943MedJan 16, 2026
    risk 0.30cvss —epss 0.00

    Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.

  • CVE-2021-36057LowSep 1, 2021
    risk 0.21cvss 3.3epss 0.01

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service…