The software reads data past the end, or before the beginning, of the intended buffer.
Under-studied and under-reported. Most issues are probably labeled as buffer overflows.
CWE is a Software Assurance strategic initiative sponsored by the National Cyber Security Division of the U.S. Department of Homeland Security.
This Web site is hosted by The MITRE Corporation.Copyright 2009, The MITRE Corporation. CWE and the CWE logo are trademarks of The MITRE Corporation.
Contact cwe@mitre.org for more information.