Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-122

MITRE ↗

CWE-122

257
CRITICAL
1,911
HIGH
479
MEDIUM
65
LOW
2,756 CVEs · Page 12/56
7.8
CVE-2026-68804

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68805

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68807

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68812

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68815

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-70345

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-70347

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-49429

The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer fo

7.8
CVE-2026-49430

The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for

7.8
CVE-2026-75141

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration

7.8
CVE-2026-75144

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat

7.8
CVE-2026-18296

GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem

7.8
CVE-2026-18298

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem

7.8
CVE-2026-18302

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2026-18307

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a

7.8
CVE-2026-48422

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48423

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48424

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48425

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48428

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48430

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48431

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48432

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48433

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-75750

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75766

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75767

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75769

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-58097

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the

7.8
CVE-2026-77652

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/w

7.8
CVE-2026-34674

Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r

7.7
CVE-2026-20185

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG

7.7
CVE-2026-61390

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca

7.6
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco

7.5
CVE-2026-22697

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL

7.5
CVE-2026-23732

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbDa

7.5
CVE-2025-62601

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).

7.5
CVE-2025-62602

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).

7.5
CVE-2026-24682

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an inc

7.5
CVE-2025-67433

A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a

7.5
CVE-2025-70122

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of

7.5
CVE-2026-2474

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_

7.5
CVE-2025-69247

free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Vers

7.5
CVE-2026-2597

Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by

7.5
CVE-2006-10002

XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double

7.5
CVE-2026-33164

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u

7.5
CVE-2026-28842

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may resu

7.5
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf

7.5
CVE-2026-33986

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf

7.5
CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade

Frequently Asked Questions

What is CWE-122?

CWE-122 (CWE-122) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-122?

There are 2,806 CVE records associated with CWE-122 in our database. Of these, 257 are critical severity, 1911 are high severity, and 479 are medium severity.

How can I protect against CWE-122 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-122 using AI-powered security agents.

Detect CWE-122 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-122 vulnerabilities across your infrastructure.

Get Started