Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-122

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,527
Assigned CVEs
30th
Commonality Rank
7.9
Avg CVSS
0.7%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-122 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2009
16 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

2,527 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4911HIGH
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
CVE-2015-3113CRITICAL
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack
Jun 23, 20159.898YESYES
CVE-2009-3459HIGH
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF fi
Oct 13, 20098.897YESYES
CVE-2023-27997CRITICAL
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy
Jun 13, 20239.895YESNO
CVE-2021-21017HIGH
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnera
Feb 11, 20218.894YESNO
CVE-2024-38812CRITICAL
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul
Sep 17, 20249.890YESNO
CVE-2023-28252HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Apr 11, 20237.889YESYES
CVE-2019-3568CRITICAL
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects W
May 14, 20199.886YESNO
CVE-2024-49138HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Dec 12, 20247.885YESYES
CVE-2026-42945HIGH
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or s
May 13, 20268.179NONO
View all 2,527 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
16%
6.0-6.9
46%
26%
7.0-7.9
26%
11%
8.0-8.9
13%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
17 CVEs
0.7% of CVEs· 87th percentile
Metasploit
7 CVEs
0.3% of CVEs· 80th percentile
Nuclei
2 CVEs
0.1% of CVEs· 77th percentile
ExploitDB
16 CVEs
0.6% of CVEs· 77th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products