CWE-123: Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
38 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-42479 — llama.cpp allows write-what-where in rpc_server::set_tensor
- CVE-2025-62164 — VLLM deserialization vulnerability leading to DoS and potential RCE
- CVE-2025-33045 — Legacy Serial Redirection SMRAM Vulnerabilities
- CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()
- CVE-2025-7403 — Bluetooth: bt_conn_tx_processor unsafe handling
- CVE-2025-55298 — ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution
- CVE-2026-81579 — An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
- CVE-2026-45257 — Arbitrary file overwrite via the KTLS receive path
- CVE-2026-41952 — Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP
- CVE-2026-47473 — NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex
- CVE-2024-47438 — Substance3D - Painter | Write-what-where Condition (CWE-123)
- CVE-2026-20469 — In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e
- CVE-2025-29943 — Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU
- CVE-2025-14857 — Semtech LR11xx Memory Write Access Control Bypass
- CVE-2024-20141 — In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
Recently published
- CVE-2026-81579 — An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
- CVE-2026-20469 — In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e
- CVE-2026-47473 — NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex
- CVE-2026-45257 — Arbitrary file overwrite via the KTLS receive path
- CVE-2026-41952 — Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP
- CVE-2025-14857 — Semtech LR11xx Memory Write Access Control Bypass
- CVE-2026-25634 — iccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()
- CVE-2025-29943 — Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU
- CVE-2025-62164 — VLLM deserialization vulnerability leading to DoS and potential RCE
- CVE-2025-7403 — Bluetooth: bt_conn_tx_processor unsafe handling
- CVE-2025-33045 — Legacy Serial Redirection SMRAM Vulnerabilities
- CVE-2025-55298 — ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution
- CVE-2024-20141 — In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
- CVE-2024-47438 — Substance3D - Painter | Write-what-where Condition (CWE-123)
- CVE-2024-42479 — llama.cpp allows write-what-where in rpc_server::set_tensor