CWE-118: Incorrect Access of Indexable Resource ('Range Error')
The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.
Last updated
Overview
CWE-118 (Incorrect Access of Indexable Resource ('Range Error')) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
12 recorded CVEs are caused by CWE-118 (Incorrect Access of Indexable Resource ('Range Error')). The highest-severity and most recent are shown first. 1 new CWE-118 CVE has been recorded so far in 2026 (2 in 2025).
- CVE-2022-38072High · CVSS 8.8 · EPSS 62th2023-04-03
- CVE-2026-50367
Windows Sensor Data Service Elevation of Privilege Vulnerability
High · CVSS 7.8 · EPSS 26th2026-07-14 - CVE-2023-37923High · CVSS 7.8 · EPSS 36th2024-01-08
- CVE-2023-37922High · CVSS 7.8 · EPSS 36th2024-01-08
- CVE-2023-37921High · CVSS 7.8 · EPSS 36th2024-01-08
- CVE-2020-3235High · CVSS 7.7 · EPSS 74th2020-06-03
- CVE-2025-54628High · CVSS 7.5 · EPSS 13th2025-08-06
- CVE-2020-3369
Cisco SD-WAN vEdge Routers Denial of Service Vulnerability
High · CVSS 7.5 · EPSS 71th2020-07-16 - CVE-2024-43524
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Medium · CVSS 6.8 · EPSS 49th2024-10-08 - CVE-2023-0201Medium · CVSS 6.7 · EPSS 10th2023-04-22
- CVE-2025-48902Medium · CVSS 6.6 · EPSS 0th2025-06-06
- CVE-2022-36402Medium · CVSS 6.3 · EPSS 40th2022-09-16
Common consequences
What can happen when CWE-118 is exploited.
Varies by Context
Affects: Other
How it happens
When it is introduced
Typically introduced during these phases of the software lifecycle.
Terminology & mappings
Mapped taxonomies
- Software Fault Patterns: Faulty Buffer Access (SFP8)
Attack patterns
CAPEC attack patterns that exploit this weakness.
- CAPEC-10: Buffer Overflow via Environment Variables
- CAPEC-14: Client-side Injection-induced Buffer Overflow
- CAPEC-24: Filter Failure through Buffer Overflow
- CAPEC-45: Buffer Overflow via Symbolic Links
- CAPEC-46: Overflow Variables and Tags
- CAPEC-47: Buffer Overflow via Parameter Expansion
- CAPEC-8: Buffer Overflow in an API Call
- CAPEC-9: Buffer Overflow in Local Command-Line Utilities
Frequently asked questions
Common questions about CWE-118.
- What is CWE-118?
- The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.
- What CVEs are caused by CWE-118?
- 12 recorded CVEs are attributed to CWE-118, including CVE-2022-38072, CVE-2026-50367, CVE-2023-37923.
- What are the consequences of CWE-118?
- Exploiting CWE-118 can lead to: Varies by Context.
- Is CWE-118 actively exploited?
- 12 recorded CVEs are caused by CWE-118; none are currently in CISA's KEV catalog of actively exploited flaws.
References
- MITRE CWE definition (CWE-118) (opens in a new tab)
- CWE-118 vulnerabilities on NVD (opens in a new tab)
- Learn: What is a CWE?
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Stay ahead of CWE-118
Get alerted the moment a new CWE-118 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.