BaseDraftTop 25 #2

CWE-787Out-of-bounds Write

Category: memory

Description

The product writes data past the end, or before the beginning, of the intended buffer.

Common consequences· 3

  • Integrity — Modify Memory, Execute Unauthorized Code or Commands
    Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
  • Availability — DoS: Crash, Exit, or Restart
    Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
  • Other — Unexpected State
    Subsequent write operations can produce undefined or unexpected results.

Potential mitigations· 5

  • [Requirements]
  • [Architecture and Design]
  • [Operation, Build and Compilation]
  • [Implementation]
  • [Operation, Build and Compilation]

References

  1. https://cwe.mitre.org/data/definitions/787.html

Compliance frameworks addressing this (incoming)6

TypeTargetConfidenceTier
ComplianceControldora-art11100%live
ComplianceControlnis2-art21e100%live
ComplianceControldora-art25100%live
ComplianceControlnist_csf-rc100%live
ComplianceControlnis2-art21d100%live
ComplianceControlcra-art13100%live

(incoming)144

TypeTargetConfidenceTier
VulnerabilityCVE-2025-0247cve-2025-02470%live
VulnerabilityIvanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerabilitycve-2025-02820%live
VulnerabilityCVE-2025-0349cve-2025-03490%live
VulnerabilityCVE-2025-0566cve-2025-05660%live
VulnerabilityCVE-2025-0848cve-2025-08480%live
VulnerabilityCVE-2025-0903cve-2025-09030%live
VulnerabilityCVE-2025-0910cve-2025-09100%live
VulnerabilityCVE-2025-10101cve-2025-101010%live
VulnerabilityCVE-2025-1016cve-2025-10160%live
VulnerabilityCVE-2025-1017cve-2025-10170%live
VulnerabilityCVE-2025-1020cve-2025-10200%live
VulnerabilityCVE-2025-10451cve-2025-104510%live
VulnerabilityCVE-2025-1050cve-2025-10500%live
VulnerabilityCVE-2025-1051cve-2025-10510%live
VulnerabilityCVE-2025-1052cve-2025-10520%live
VulnerabilityCVE-2025-10773cve-2025-107730%live
VulnerabilityCVE-2025-10779cve-2025-107790%live
VulnerabilityCVE-2025-10792cve-2025-107920%live
VulnerabilityCVE-2025-11205cve-2025-112050%live
VulnerabilityCVE-2025-11458cve-2025-114580%live
VulnerabilityCVE-2025-11541cve-2025-115410%live
VulnerabilityCVE-2025-11542cve-2025-115420%live
VulnerabilityCVE-2025-11624cve-2025-116240%live
VulnerabilityCVE-2025-11709cve-2025-117090%live
VulnerabilityCVE-2025-11714cve-2025-117140%live
VulnerabilityCVE-2025-1240cve-2025-12400%live
VulnerabilityCVE-2025-12602cve-2025-126020%live
VulnerabilityCVE-2025-12603cve-2025-126030%live
VulnerabilityCVE-2025-1268cve-2025-12680%live
VulnerabilityCVE-2025-12727cve-2025-127270%live

Showing top 30 of 144 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Out-of-bounds Read
CWE
Buffer Underwrite ('Buffer Underflow')
CWE
Buffer Access with Incorrect Length Value
CWE
Access of Memory Location After End of Buffer
CWE
Access of Memory Location Before Start of Buffer
CWE
Buffer Over-read
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.