Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-122

MITRE ↗

CWE-122

257
CRITICAL
1,911
HIGH
479
MEDIUM
65
LOW
2,756 CVEs · Page 10/56
7.8
CVE-2026-55120

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55123

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55125

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55127

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55129

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55130

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55131

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55133

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55137

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55140

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55947

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-56156

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-56175

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-56189

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally

7.8
CVE-2026-56650

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-57096

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate

7.8
CVE-2026-58530

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local

7.8
CVE-2026-58538

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58542

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-24268

NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploi

7.8
CVE-2026-24272

NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful

7.8
CVE-2026-48269

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in

7.8
CVE-2026-48339

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co

7.8
CVE-2026-48373

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.8
CVE-2026-35591

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an

7.8
CVE-2026-48372

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.8
CVE-2026-16463

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m

7.8
CVE-2026-14266

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2026-70638

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th

7.8
CVE-2026-54984

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-58651

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-61353

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61355

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61359

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61923

Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges lo

7.8
CVE-2026-61926

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61930

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker

7.8
CVE-2026-61937

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62688

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62692

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locall

7.8
CVE-2026-62695

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62700

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62710

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges loc

7.8
CVE-2026-62712

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62713

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges

7.8
CVE-2026-62717

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62719

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62722

Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

Frequently Asked Questions

What is CWE-122?

CWE-122 (CWE-122) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-122?

There are 2,806 CVE records associated with CWE-122 in our database. Of these, 257 are critical severity, 1911 are high severity, and 479 are medium severity.

How can I protect against CWE-122 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-122 using AI-powered security agents.

Detect CWE-122 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-122 vulnerabilities across your infrastructure.

Get Started