CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 42 of 52
- CVE-2026-23750HIGHCVSS 8.1EG 8.12026-02-26
Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the f…
- CVE-2026-23827HIGHCVSS 7.5EG 7.52026-05-12
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthentica…
- CVE-2026-23876CRITICALCVSS 9.8EG 9.82026-01-20
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to wri…
- CVE-2026-24180HIGHCVSS 7.3EG 7.32026-06-09
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information dis…
- CVE-2026-24268HIGHCVSS 7.8EG 7.82026-07-14
NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.
- CVE-2026-24272HIGHCVSS 7.8EG 7.82026-07-14
NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.
- CVE-2026-24283HIGHCVSS 8.8EG 8.82026-03-10
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-24288MEDIUMCVSS 6.8EG 6.82026-03-10
Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-24405HIGHCVSS 8.8EG 8.82026-01-24
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccMpeCalculator::Read(). This occurs when user-co…
- CVE-2026-24406HIGHCVSS 8.8EG 8.82026-01-24
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buffer Overflow vulnerability in CIccTagNamedColor2::SetSize(). This occurs when use…
- CVE-2026-24412HIGHCVSS 8.8EG 8.82026-01-24
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffer Overflow vulnerability in the CIccTagXmlSegmentedCurve::ToXml() function. This…
- CVE-2026-2447HIGHCVSS 8.8EG 8.82026-02-16
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
- CVE-2026-2467HIGHCVSS 8.1EG 8.12026-06-17
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, …
- CVE-2026-24679CRITICALCVSS 9.1EG 9.12026-02-09
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interfac…
- CVE-2026-24682HIGHCVSS 7.5EG 7.52026-02-09
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an incorrect number of audio formats on parse failure (i + i), leading to out-of-bounds access in audio_formats_free. This vu…
- CVE-2026-2474HIGHCVSS 7.5EG 7.52026-02-16
Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.…
- CVE-2026-24822CRITICALCVSS 10.0EG 10.02026-01-27
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.
- CVE-2026-24829MEDIUMCVSS 6.5EG 6.52026-01-27
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.
- CVE-2026-24852MEDIUMCVSS 8.1EG 6.12026-01-28
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, a heap buffer over-read when the strlen() function attempts to read a no…
- CVE-2026-24857CRITICALCVSS 9.8EG 9.82026-01-28
`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑…
- CVE-2026-24922MEDIUMCVSS 5.5EG 6.92026-02-06
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-24925HIGHCVSS 5.5EG 7.32026-02-06
Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-25172HIGHCVSS 8.0EG 8.82026-03-10
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2026-25173HIGHCVSS 8.0EG 8.02026-03-10
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2026-25188HIGHCVSS 8.8EG 8.82026-03-10
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
- CVE-2026-25205HIGHCVSS 7.4EG 7.42026-04-13
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335 .
- CVE-2026-25243HIGHCVSS 8.8EG 8.82026-05-05
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serial…
- CVE-2026-25576MEDIUMCVSS 5.5EG 5.52026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability o…
- CVE-2026-25582HIGHCVSS 7.8EG 7.82026-02-04
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow (read) vulnerability in CIccIO::WriteUIn…
- CVE-2026-25583HIGHCVSS 7.8EG 7.82026-02-04
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow vulnerability in CIccFileIO::Read8() whe…
- CVE-2026-25588HIGHCVSS 8.8EG 8.82026-05-05
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permi…
- CVE-2026-25589HIGHCVSS 8.8EG 8.82026-05-05
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker wit…
- CVE-2026-25646HIGHCVSS 8.1EG 8.12026-02-10
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function.…
- CVE-2026-25713HIGHCVSS 7.8EG 7.82026-05-26
MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
- CVE-2026-25749MEDIUMCVSS 6.6EG 6.62026-02-06
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfn…
- CVE-2026-25794HIGHCVSS 8.2EG 8.22026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are…
- CVE-2026-25897CRITICALCVSS 9.8EG 9.82026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully cra…
- CVE-2026-2597HIGHCVSS 7.5EG 7.52026-02-27
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supp…
- CVE-2026-26011CRITICALCVSS 9.8EG 9.82026-02-12
navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithC…
- CVE-2026-26073MEDIUMCVSS 5.9EG 5.92026-03-26
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not starte…
- CVE-2026-26108HIGHCVSS 7.8EG 7.82026-03-10
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-26111HIGHCVSS 8.0EG 8.82026-03-10
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2026-26156HIGHCVSS 7.8EG 7.82026-04-14
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- CVE-2026-26176HIGHCVSS 7.8EG 7.82026-04-14
Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-26180HIGHCVSS 7.8EG 7.82026-04-14
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-26200HIGHCVSS 7.8EG 7.82026-02-19
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentiall…
- CVE-2026-26284CRITICALCVSS 9.1EG 9.12026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) file…
- CVE-2026-2646HIGHCVSS 8.1EG 8.12026-03-19
A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read from an untrusted input without bounds val…
- CVE-2026-2648HIGHCVSS 8.8EG 8.82026-02-18
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-2650HIGHCVSS 8.8EG 8.82026-02-18
Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →