Cyber Posture

CWE · MITRE source

CWE-123Write-what-where Condition

Abstraction: Base · CVEs in our corpus: 48

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SI-16Memory ProtectionSIWrite-what-where primitives are neutralized when the attacker cannot execute the memory they control.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-22225 KEV4.28.20.09982025-03-04
CVE-2024-424792.310.00.05682024-08-12
CVE-2015-82712.09.80.01182017-04-13
CVE-2014-54352.09.80.01432019-04-08
CVE-2021-384492.09.80.00272021-10-22
CVE-2022-381432.09.80.00722022-12-22
CVE-2025-698092.09.80.00072026-03-16
CVE-2022-417571.88.80.00472022-11-08
CVE-2024-368771.88.20.03442024-08-12
CVE-2025-99001.88.80.00042025-09-23
CVE-2025-621641.88.80.00192025-11-21
CVE-2020-20011.78.10.01522020-05-13
CVE-2020-75601.78.60.00422020-12-11
CVE-2024-26071.78.10.01452024-03-19
CVE-2024-440671.78.40.00052024-08-19
CVE-2017-62821.67.80.00012018-03-06
CVE-2018-120361.67.80.00182018-06-07
CVE-2018-169621.67.80.00132018-09-12
CVE-2018-39711.67.80.00022018-10-25
CVE-2020-162251.67.80.00212020-08-07
CVE-2021-425401.68.00.00222021-10-22
CVE-2022-402621.68.20.00062022-09-20
CVE-2022-354081.68.20.00082022-09-22
CVE-2021-454651.67.80.00042024-01-04
CVE-2024-207411.67.80.00152024-02-15