Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
Volume of CVEs assigned to CWE-123 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43284HIGH In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly t | May 8, 2026 | 8.8 | 95 | NO | YES |
CVE-2026-43500HIGH In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
The DATA-packet handler in rxrpc_input_ | May 11, 2026 | 7.8 | 94 | NO | YES |
CVE-2025-22225HIGH VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sa | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2026-46300HIGH In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: preserve shared-frag marker during coalescing
skb_try_coalesce() can attach paged frags from @fro | May 23, 2026 | 7.8 | 53 | NO | YES |
CVE-2026-45257HIGH The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data place | Jun 26, 2026 | 7.8 | 37 | NO | NO |
CVE-2025-69809CRITICAL A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted pa | Mar 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2024-42479CRITICAL llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561. | Aug 12, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-46323HIGH In the Linux kernel, the following vulnerability has been resolved:
net: gro: don't merge zcopy skbs
skb_gro_receive() can currently copy frags between the source and GRO
skb, wi | Jun 9, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-62164HIGH vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of- | Nov 21, 2025 | 8.8 | 32 | NO | NO |
CVE-2025-9900HIGH A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file.
By providing an abnorm | Sep 23, 2025 | 8.8 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.