A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is
A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices.
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. Wh
A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::c
vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)
A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for th
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address
A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when
entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a fixed-size heap buf
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[]
Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accep
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF proc
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE de
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unus
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to ex
A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used t
Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompre
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffe
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local
Frequently Asked Questions
What is CWE-122?
CWE-122 (CWE-122) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-122?
There are 2,806 CVE records associated with CWE-122 in our database. Of these, 257 are critical severity, 1911 are high severity, and 479 are medium severity.
How can I protect against CWE-122 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-122 using AI-powered security agents.
Detect CWE-122 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-122 vulnerabilities across your infrastructure.
Get Started