Falhas do tipo CWE-123

52 resultados

Condição de escrita arbitrária em memória

É uma fraqueza onde o atacante consegue escrever dados arbitrários em um endereço de memória arbitrário, tipicamente explorando falta de validação em ponteiros ou índices. O risco é crítico: permite sobrescrever dados sensíveis, alterar fluxo de controle ou elevar privilégios.

Exemplo

Um programa recebe um índice e um valor do usuário sem validar, depois escreve o valor em um array usando esse índice. Um atacante fornece um índice fora dos limites, escrevendo sobre variáveis críticas ou endereços de retorno na stack.

Como mitigar

Valide rigorosamente todos os índices e ponteiros antes de usá-los para acesso à memória; use linguagens de mais alto nível quando possível (que fazem bounds-checking automático); aplique técnicas como ASLR e canários de stack para dificultar exploração.

CVE-2021-36057MEDIUMXMP Toolkit SDK Write-What-Where Condition Could Lead To Local Application Denial Of ServiceEPSS 0.6%CVE-2025-69809CRITICALA write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling aEPSS 0.5%CVE-2022-1523MEDIUMFuji Electric D300win Write-what-where conditionEPSS 0.5%CVE-2022-40246HIGHArbitrary write vulnerability in SbPei module leads to arbitrary code execution during PEI phase.EPSS 0.5%CVE-2022-35408HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSEPSS 0.3%CVE-2021-1390MEDIUMCisco IOS XE Software Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2018-15376Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers Arbitrary Memory Write VulnerabilitiesEPSS 0.3%CVE-2018-15375Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers Arbitrary Memory Write VulnerabilitiesEPSS 0.3%CVE-2022-40262HIGHThe arbitrary write vulnerability in S3Resume2Pei leads to arbitrary code execution during PEI phase.EPSS 0.3%CVE-2026-30121CRITICALremotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.EPSS 0.3%CVE-2021-45465HIGHA vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied dataEPSS 0.3%CVE-2024-45142HIGHSubstance3D - Stager | Write-what-where Condition (CWE-123)EPSS 0.3%CVE-2026-48977HIGHOpenSlide: Arbitrary memory write with crafted Ventana BIF fileEPSS 0.3%CVE-2021-1520MEDIUMCisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2024-20741HIGHAdobe Substance 3D Paint ICO Parsing Access Violation Write VulnerabilityEPSS 0.3%CVE-2024-44067HIGHThe T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivilegedEPSS 0.2%CVE-2025-14857MEDIUMSemtech LR11xx Memory Write Access Control BypassEPSS 0.2%CVE-2025-29943MEDIUMWrite what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentiallyEPSS 0.2%CVE-2024-47438MEDIUMSubstance3D - Painter | Write-what-where Condition (CWE-123)EPSS 0.2%CVE-2024-6563HIGHBuffer Overflow Arbitrary WriteEPSS 0.2%