CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 41 of 52
- CVE-2026-20809HIGHCVSS 7.8EG 7.82026-01-13
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
- CVE-2026-20820HIGHCVSS 7.8EG 7.82026-01-13
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-20837HIGHCVSS 7.8EG 7.82026-01-13
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
- CVE-2026-20840HIGHCVSS 7.8EG 7.82026-01-13
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-20864HIGHCVSS 7.8EG 7.82026-01-13
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2026-20868HIGHCVSS 8.8EG 8.82026-01-13
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2026-20876MEDIUMCVSS 6.7EG 6.72026-01-13
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- CVE-2026-20922HIGHCVSS 7.8EG 7.82026-01-13
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-20957HIGHCVSS 7.8EG 7.82026-01-13
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-21236HIGHCVSS 7.8EG 7.82026-02-10
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-21239HIGHCVSS 7.8EG 7.82026-02-10
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-21244HIGHCVSS 7.3EG 7.32026-02-10
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-21245HIGHCVSS 7.8EG 7.82026-02-10
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-21246HIGHCVSS 7.8EG 7.82026-02-10
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2026-21247HIGHCVSS 7.3EG 7.32026-02-10
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-21248HIGHCVSS 7.3EG 7.32026-02-10
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-21259HIGHCVSS 7.8EG 7.82026-02-10
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-21277HIGHCVSS 7.8EG 7.82026-01-13
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2026-21281HIGHCVSS 7.8EG 7.82026-01-13
InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t…
- CVE-2026-21283HIGHCVSS 7.8EG 7.82026-01-13
Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t…
- CVE-2026-21304HIGHCVSS 7.8EG 7.82026-01-13
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2026-21357HIGHCVSS 7.8EG 7.82026-02-10
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera…
- CVE-2026-21358MEDIUMCVSS 5.5EG 5.52026-02-10
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causin…
- CVE-2026-21372HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
- CVE-2026-21486HIGHCVSS 7.8EG 7.82026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write vulnerabi…
- CVE-2026-21488MEDIUMCVSS 7.1EG 6.12026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText:…
- CVE-2026-21490MEDIUMCVSS 7.1EG 6.12026-01-06
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects user…
- CVE-2026-21491MEDIUMCVSS 7.1EG 6.12026-01-06
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects user…
- CVE-2026-21494MEDIUMCVSS 7.1EG 6.12026-01-06
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects user…
- CVE-2026-21504MEDIUMCVSS 7.8EG 6.62026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This…
- CVE-2026-21676HIGHCVSS 8.8EG 8.82026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its CIccMBB::Validate function which checks tag data validity. This issue is fixed i…
- CVE-2026-21678HIGHCVSS 7.8EG 7.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow vulnerability in IccTagXml(…
- CVE-2026-21682HIGHCVSS 8.8EG 8.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow in `CIccXml…
- CVE-2026-22027MEDIUMCVSS 6.0EG 6.02026-01-10
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to…
- CVE-2026-22164HIGHCVSS 7.5EG 7.52026-06-08
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types and presenting a set of parameters to the affected interface the exploit can…
- CVE-2026-22554HIGHCVSS 7.8EG 7.82026-05-20
MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
- CVE-2026-22697HIGHCVSS 7.5EG 7.52026-01-10
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to…
- CVE-2026-22828HIGHCVSS 8.1EG 8.12026-04-14
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically craft…
- CVE-2026-22854CRITICALCVSS 9.8EG 9.82026-01-14
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard up…
- CVE-2026-22891CRITICALCVSS 9.8EG 9.82026-03-03
A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attack…
- CVE-2026-2314HIGHCVSS 8.8EG 8.82026-02-11
Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-23530CRITICALCVSS 9.8EG 9.82026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious se…
- CVE-2026-23531CRITICALCVSS 9.8EG 9.82026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, al…
- CVE-2026-23532CRITICALCVSS 9.8EG 9.82026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clam…
- CVE-2026-23533CRITICALCVSS 9.8EG 9.82026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes out-of-bounds writes dur…
- CVE-2026-23534CRITICALCVSS 9.8EG 9.82026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destinat…
- CVE-2026-23567MEDIUMCVSS 6.5EG 6.52026-01-29
An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buf…
- CVE-2026-23665HIGHCVSS 7.8EG 7.82026-03-10
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
- CVE-2026-23719HIGHCVSS 7.3EG 7.82026-02-10
A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This c…
- CVE-2026-23732HIGHCVSS 7.5EG 7.52026-01-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and never validates against the minimum size implied by `cx/cy`. A malicious server can trigger a …
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →