Cyber Posture

CWE · MITRE source

CWE-122Heap-based Buffer Overflow

Abstraction: Variant · CVEs in our corpus: 2,148

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2015-3113 KEV9.59.80.92502015-06-23
CVE-2023-27997 KEV9.39.80.88902023-06-13
CVE-2021-21017 KEV9.28.80.90202021-02-11
CVE-2024-38812 KEV8.69.80.77872024-09-17
CVE-2024-49138 KEV8.67.80.84832024-12-12
CVE-2025-21333 KEV8.57.80.82282025-01-14
CVE-2023-4911 KEV7.67.80.67192023-10-03
CVE-2024-380777.49.80.90282024-07-09
CVE-2023-28252 KEV7.37.80.62442023-04-11
CVE-2024-43237.09.80.84642024-05-20
CVE-2019-3568 KEV6.89.80.47962019-05-14
CVE-2023-368246.87.40.89002023-07-11
CVE-2024-262296.77.80.85762024-04-09
CVE-2023-282316.38.80.75512023-04-11
CVE-2024-30051 KEV6.27.80.43532024-05-14
CVE-2023-444425.27.80.60332024-05-03
CVE-2020-16010 KEV5.19.60.19632020-11-03
CVE-2023-23376 KEV4.97.80.22552023-02-14
CVE-2024-300854.97.80.55242024-06-11
CVE-2021-266914.89.80.47822021-06-10
CVE-2024-206974.47.30.49432024-01-09
CVE-2025-21418 KEV4.47.80.13272025-02-11
CVE-2020-256814.38.10.45362021-01-20
CVE-2021-285584.38.80.41542021-09-02
CVE-2021-286384.17.80.42202021-08-20