xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the Neu
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali
As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules.
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string express
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execu
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute cod
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output pa
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to ca
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. T
Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilit
Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proxi
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n
Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all
Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate priv
Frequently Asked Questions
What is CWE-122?
CWE-122 (CWE-122) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-122?
There are 2,806 CVE records associated with CWE-122 in our database. Of these, 257 are critical severity, 1911 are high severity, and 479 are medium severity.
How can I protect against CWE-122 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-122 using AI-powered security agents.
Detect CWE-122 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-122 vulnerabilities across your infrastructure.
Get Started