Statistics

Buffer Overflow Statistics: Historical Prevalence, Severity, and Exploitation Signals

Buffer overflow statistics from MITRE, ENISA, CISA, and NVD, covering prevalence, rankings, severity, and exploitation indicators.

Buffer overflow statistics show a sharp change in the historical record: MITRE’s buffer-overflow category represented 19.5% of all reported CVEs in 2001, but 7.8% in 2006. Recent datasets still show high-impact cases. ENISA counted 464 CWE-120 occurrences from July 2022 through June 2023, with an average CVSSv3 base score of 8.4.

Contents

Historical prevalence across CVEs

The historical MITRE series measures its buf category across CVE reports. MITRE’s glossary maps that category to CWE-119 and CWE-120, so these figures should not be treated as directly comparable with newer datasets that isolate a single CWE. Within that historical classification, buffer-overflow reports were the leading reported flaw type in 2001, 2002, 2003, and 2004.

In 2001, MITRE recorded 279 buffer-overflow reports among 1,432 total CVEs, or 19.5%. The category ranked first among all reported flaw types. In 2002, the count rose to 436 of 2,138 CVEs, representing 20.4%, and it again ranked first. In 2003, there were 268 buffer-overflow reports among 1,190 CVEs, a 22.5% share, also ranked first.

The share then declined. MITRE recorded 392 buffer-overflow reports among 2,546 CVEs in 2004, or 15.4%, while the category still ranked first. In 2005, the count was 445 among 4,559 CVEs, equal to 9.8%, and the category ranked third. In 2006, MITRE recorded 541 among 6,944 CVEs, or 7.8%, with a fourth-place ranking.

YearBuffer-overflow reportsTotal CVEsShareOverall rank
20012791,43219.5%1
20024362,13820.4%1
20032681,19022.5%1
20043922,54615.4%1
20054454,5599.8%3
20065416,9447.8%4

Source: CWE - Vulnerability Type Distributions in CVE. These are MITRE’s historical buf classifications, not independently reconstructed counts.

The peak share in this series was 22.5% in 2003. The largest count was 541 in 2006, even though the percentage was lower because the total number of CVEs was much larger. That distinction matters when comparing prevalence: a larger count does not necessarily mean a larger share of reported vulnerabilities.

Operating-system and non-OS distributions

MITRE also separated OS-vendor advisories from non-OS issues. The OS-vendor series remained especially concentrated in buffer-overflow reports. In 2001, 93 of 443 OS-vendor advisories were buffer overflows, or 21.0%, and the category ranked first among OS-vendor flaw types. In 2002, the count was 178 of 664, or 26.8%, again ranked first.

For 2003, MITRE recorded 131 buffer-overflow reports among 530 OS-vendor advisories, equal to 24.7%. The category remained first. In 2004, 152 of 745 OS-vendor advisories were buffer overflows, or 20.4%, still first. The 2005 count was 195 of 1,216, or 16.0%, and the category again ranked first. In 2006, 209 of 1,295 OS-vendor advisories were buffer overflows, or 16.1%, also first.

The non-OS series was lower in every year except that it followed the same broad decline. In 2001, MITRE recorded 186 buffer-overflow reports among 989 non-OS issues, or 18.8%, ranked first. In 2002, there were 258 among 1,474, or 17.5%, again ranked first. The 2003 count was 137 among 660, or 20.8%, ranked first.

In 2004, buffer overflows accounted for 240 of 1,801 non-OS issues, or 13.3%; the category ranked second. In 2005, the count was 250 of 3,343, or 7.5%, ranked third. In 2006, 332 of 5,649 non-OS issues were buffer overflows, or 5.9%, ranked fourth.

YearOS-vendor shareOS rankNon-OS shareNon-OS rank
200121.0%118.8%1
200226.8%117.5%1
200324.7%120.8%1
200420.4%113.3%2
200516.0%17.5%3
200616.1%15.9%4

Source: CWE - Vulnerability Type Distributions in CVE. The OS-vendor and non-OS populations are separate reporting groups.

The highest OS-vendor share was 26.8% in 2002. The highest non-OS share was 20.8% in 2003. These comparisons describe the historical MITRE populations and classification rules; they do not establish that modern operating systems or non-OS software have the same distribution.

Recent ENISA and CISA measurements

ENISA’s July 2022–June 2023 vulnerability dataset provides a more recent, CWE-specific measurement. It counted 464 CWE-120 occurrences, where CWE-120 describes copying a buffer without checking its size. The average CVSSv3 base score for those 464 occurrences was 8.4. ENISA also counted 210 CWE-120 vulnerabilities among critical-severity CVEs.

The ENISA dataset included a smaller exploitation-related comparison. During the report’s 2022–2023 time frame, ENISA compared 76 vulnerabilities added to its KEV-related set and counted 2 CWE-120 vulnerabilities among them. This is a count within that comparison, not an estimate of the total number of exploited buffer overflows.

Source: ENISA Threat Landscape 2023. ENISA’s extracted average is 8.4; the PDF table displays the value as 8,419,828 because of decimal formatting.

CISA’s ICS-CERT figures offer a different view from industrial-control vulnerability coordination. In FY2016, ICS-CERT assigned CWE-121 to 97 validated vulnerabilities and CWE-122 to 19 validated vulnerabilities. In CY2016, it assigned CWE-121 to 102 validated vulnerabilities and CWE-122 to 32 validated vulnerabilities.

CWE-121 is the stack-based buffer overflow category, while CWE-122 is the heap-based buffer overflow category. The FY2016 and CY2016 counts are separate reporting periods, so they should not be added together or treated as a single annual total.

Source: ICS-CERT Annual Vulnerability Coordination Report 2016.

Risk rankings and exploitation indicators

MITRE’s 2025 CWE Top 25 gives three related categories separate positions. CWE-120 ranked 11th with a score of 6.96. The table reported 0 CISA KEV CVEs for CWE-120. CWE-121 ranked 14th with a score of 5.75 and had 4 CISA KEV CVEs. CWE-122 ranked 16th with a score of 5.21 and had 6 CISA KEV CVEs.

Weakness2025 Top 25 rankScoreCISA KEV CVEs
CWE-120116.960
CWE-121145.754
CWE-122165.216

Source: 2025 CWE Top 25 Most Dangerous Software Weaknesses. The ranking score and KEV count measure different things: one is a risk-ranking score, while the other counts CVEs in CISA’s Known Exploited Vulnerabilities catalog.

An earlier MITRE CWSS prevalence assessment scored classic buffer overflow, CWE-120, at 6.04 on its 1–10 prevalence scale in the 2010 Top 25 scoring data. That older score is a historical measurement and should not be read as a current prevalence estimate.

Source: Common Weakness Scoring System (CWSS).

The 2025 figures therefore show a useful distinction. CWE-120 had the highest rank and score among these three categories, but CWE-122 had the largest CISA KEV count. A ranking position is not the same as an exploitation count, and neither is a direct measure of how often a flaw appears in all software.

Recent NVD severity examples

NVD records from 2024 illustrate the range of severity scores associated with specific buffer-overflow vulnerabilities. NVD lists CVE-2024-38812 as a VMware vCenter heap-based buffer overflow with a CVSS 3.1 base score of 9.8, rated Critical.

NVD lists CVE-2024-6994 as a Chrome heap-based buffer overflow with a CVSS 3.1 base score of 8.8, rated High. NVD lists CVE-2024-20880 as a Samsung bootloader stack-based buffer overflow with a NIST CVSS 3.1 base score of 6.8, rated Medium.

Sources: NVD - CVE-2024-38812, NVD - CVE-2024-6994, and NVD - CVE-2024-20880.

CVEContextCVSS 3.1 base scoreRating
CVE-2024-38812VMware vCenter heap-based buffer overflow9.8Critical
CVE-2024-6994Chrome heap-based buffer overflow8.8High
CVE-2024-20880Samsung bootloader stack-based buffer overflow6.8Medium

These examples are severity measurements for individual CVEs, not prevalence estimates. They also show why a buffer-overflow statistic needs its unit of analysis: a weakness category, a vendor-advisory population, an exploited-vulnerability set, or an individual vulnerability can produce very different numbers.

How to interpret these statistics

The historical MITRE figures show buffer overflows moving from the leading reported category in 2001–2004 to fourth overall in 2006. The OS-vendor share stayed above the non-OS share in each year from 2001 through 2006, peaking at 26.8% in 2002. ENISA’s later CWE-120 dataset shows that the category remained associated with high average severity: 464 occurrences had an average CVSSv3 base score of 8.4, and 210 were counted among critical-severity CVEs.

At the same time, the datasets are not interchangeable. MITRE’s historical buf category maps to CWE-119 and CWE-120, whereas ENISA’s cited count is specifically CWE-120. CISA’s CWE-121 and CWE-122 counts concern ICS-CERT validated vulnerabilities and use separate fiscal-year and calendar-year periods. NVD’s CVSS scores describe severity, not how prevalent a weakness is. The most reliable reading is therefore to keep the source, geography or population, measurement period, classification, and metric visible with every number.

Written by

c-double.com Editorial Team

Editorial team

c-double.com publishes practical how-to guides and educational articles with clear steps and useful context.