Heap-based Buffer Overflow (CWE-122)
CWE-122 is a Variant of buffer overflow where the overwritten buffer lives in the heap, typically allocated with a routine such as malloc(). Writing past its bounds corrupts adjacent heap data. Heap overflow and heap buffer overflow are listed alternate terms.
About CWE-122
Buffer overflows generally crash the program. Heap overflows can also overwrite function pointers in memory and lead to arbitrary code execution outside the program's security policy.
Mitigations
- +Use a language or compiler that performs automatic bounds checking.
- +Implement bounds checking on input and avoid unsafe functions in favor of equivalents that enforce buffer limits.
- +Enable compiler buffer overflow detection, such as FORTIFY_SOURCE or the Visual Studio /GS flag, as defense in depth.
- +Build with ASLR and position-independent executables so memory addresses are harder to predict.
- +Use OS-level preventive features for additional defense in depth.
Detection
Fuzzing is rated highly effective. Compiler-integrated runtime checkers such as AddressSanitizer give moderate coverage and report the error condition rather than the original mistake.
CWE-122 Vulnerabilities
18 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-94127 | BIG-IP APM OAuth vulnerability | F5 | 9.8 | 2.2% | KEV | 2026-09-22 |
| CVE-2025-25249 | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Fortinet | 7.4 | 3.9% | KEV | 2026-01-13 |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Microsoft | 7.8 | 3.6% | KEV | 2026-09-08 |
| CVE-2025-24985 | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Microsoft | 7.8 | 3.9% | KEV | 2025-03-11 |
| CVE-2025-24993 | Windows NTFS Remote Code Execution Vulnerability | Microsoft | 7.8 | 2.2% | KEV | 2025-03-11 |
| CVE-2025-21418 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-02-11 |
| CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.0% | KEV | 2025-01-14 |
| CVE-2024-49138 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 26.2% | KEV | 2024-12-10 |
| CVE-2024-38812 | Heap-overflow vulnerability | - | 9.8 | 54.6% | KEV | 2024-09-17 |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 5.7% | KEV | 2024-05-14 |
| CVE-2023-4911 | Glibc: buffer overflow in ld.so leading to privilege escalation | - | 7.8 | 63.8% | KEV | 2023-10-03 |
| CVE-2023-36036 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 16.7% | KEV | 2023-11-14 |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | Fortinet | 9.2 | 85.7% | KEV | 2023-06-13 |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 49.0% | KEV | 2023-04-11 |
| CVE-2023-23376 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.9% | KEV | 2023-02-14 |
| CVE-2019-3568 | WhatsApp VOIP Stack Buffer Overflow Vulnerability | 9.8 | 30.1% | KEV | 2019-05-14 | |
| CVE-2021-21017 | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution | Adobe | 8.8 | 86.3% | KEV | 2021-02-11 |
| CVE-2026-27654 | NGINX ngx_http_dav_module vulnerability | F5 | 8.8 | 25.1% | 2026-03-24 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-122?→
CWE-122 is a heap-based buffer overflow, where a write past the end of a buffer allocated on the heap corrupts nearby memory.
Do ASLR and compiler protections eliminate heap overflows?→
No. MITRE rates them as defense in depth. They make exploitation harder but do not remove the underlying bounds error.
How many exploited vulnerabilities are classified as CWE-122?→
This database lists 18 CVE records mapped to CWE-122 by their CVE Numbering Authority. 17 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 4 to known ransomware campaigns. Examples include CVE-2026-94127, CVE-2025-25249, CVE-2026-85880.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.