Cyber Resilience

CWE · MITRE source

CWE-124Buffer Underwrite ('Buffer Underflow')

Abstraction: Base · CVEs in our corpus: 40

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Last updated: 21 August 2026 20:21 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • ID.RA-01
  • SA-11 Developer Testing and Evaluation
  • PR.PS-02
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.4.1

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2015-2426 KEV 9.28.80.86692015-07-20
CVE-2023-25610 8.59.80.18182025-03-24
CVE-2018-15361 7.89.80.02882019-03-05
CVE-2026-44631 7.39.80.00502026-06-08
CVE-2026-16439 6.79.10.00242026-07-21
CVE-2021-38575 6.58.10.01862021-12-01
CVE-2022-20683 6.58.60.01472022-04-15
CVE-2021-36064 6.37.80.02722021-09-01
CVE-2026-0966 6.38.20.00582026-03-26
CVE-2026-34253 6.38.20.00522026-05-15
CVE-2025-627866.28.10.00682025-10-29
CVE-2023-34351 6.07.50.00732024-02-14
CVE-2025-27439 6.08.50.00432025-03-11
CVE-2025-27440 6.08.50.00432025-03-11
CVE-2022-33896 5.97.80.00522022-10-07
CVE-2024-52990 5.87.80.00422024-12-10
CVE-2025-53101 5.87.40.00802025-07-14
CVE-2018-5388 5.76.50.03972018-05-31
CVE-2025-61690 5.67.80.00132025-10-02
CVE-2026-5089 5.67.30.00332026-05-12
CVE-2021-38578 5.57.40.01012022-03-03
CVE-2023-32614 5.57.00.00712023-09-25
CVE-2023-48230 5.05.90.01892023-11-21
CVE-2026-414995.06.50.00252026-04-29
CVE-2026-26199 5.06.50.00262026-07-20