CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 48 of 65
- CVE-2026-42945HIGHCVSS 8.1EG 8.72026-05-13
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expr…
- CVE-2026-42975HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-42980HIGHCVSS 7.8EG 7.82026-06-09
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-42990CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-42992HIGHCVSS 7.5EG 7.52026-06-09
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-42993HIGHCVSS 7.5EG 7.52026-06-09
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-43906HIGHCVSS 7.8EG 7.82026-05-14
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffer overflow in the HEIF decoder of OpenImageIO allows out-of…
- CVE-2026-4391MEDIUMCVSS 5.3EG 5.32026-05-27
A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to heap-based buffer overflow. The attack may be launched remot…
- CVE-2026-4395CRITICALCVSS 9.8EG 9.82026-03-19
Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC public key…
- CVE-2026-44050CRITICALCVSS 9.9EG 9.92026-05-21
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.
- CVE-2026-44178HIGHCVSS 8.8EG 8.82026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the …
- CVE-2026-44236HIGHCVSS 7.1EG 7.12026-09-17
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in lib…
- CVE-2026-44251MEDIUMCVSS 6.5EG 6.52026-07-17
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash …
- CVE-2026-4442HIGHCVSS 8.8EG 8.82026-03-20
Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-44420HIGHCVSS 8.8EG 8.82026-05-29
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too…
- CVE-2026-44421HIGHCVSS 8.8EG 8.82026-05-29
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it va…
- CVE-2026-4443HIGHCVSS 8.8EG 8.82026-03-20
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-4448HIGHCVSS 8.8EG 8.82026-03-20
Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-4455HIGHCVSS 8.8EG 8.82026-03-20
Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-4463HIGHCVSS 8.8EG 8.82026-03-20
Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-44636HIGHCVSS 7.4EG 7.42026-05-14
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode e…
- CVE-2026-44662MEDIUMCVSS 5.1EG 5.12026-05-14
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used wit…
- CVE-2026-44799HIGHCVSS 7.5EG 7.52026-06-09
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-44808HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2026-44811HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2026-44814MEDIUMCVSS 5.5EG 5.52026-06-09
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- CVE-2026-44819HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-44824HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-44950CRITICALCVSS 9.0EG 9.02026-09-10
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does n…
- CVE-2026-44983HIGHCVSS 7.3EG 7.32026-05-26
smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow …
- CVE-2026-45130MEDIUMCVSS 5.5EG 5.52026-05-08
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled len…
- CVE-2026-45252MEDIUMCVSS 5.5EG 5.52026-05-21
When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a…
- CVE-2026-45466LOWCVSS 3.3EG 3.32026-06-09
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-45469HIGHCVSS 7.8EG 7.82026-06-09
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-45475HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45515HIGHCVSS 7.8EG 7.82026-09-08
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges neede…
- CVE-2026-45531HIGHCVSS 7.8EG 7.82026-09-08
In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2026-45542HIGHCVSS 7.1EG 7.12026-06-10
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The fir…
- CVE-2026-45584HIGHCVSS 8.1EG 8.12026-05-20
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
- CVE-2026-45636HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-45638HIGHCVSS 7.8EG 7.82026-06-09
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-45653HIGHCVSS 7.0EG 7.02026-06-09
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-45657CRITICALCVSS 9.8EG 9.82026-06-09
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
- CVE-2026-45696MEDIUMCVSS 6.5EG 6.52026-06-18
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore …
- CVE-2026-45761LOWCVSS 3.3EG 3.32026-09-10
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow whi…
- CVE-2026-46520HIGHCVSS 7.5EG 7.52026-05-18
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This iss…
- CVE-2026-46655HIGHCVSS 7.8EG 7.82026-09-18
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].f…
- CVE-2026-46692MEDIUMCVSS 4.1EG 4.12026-05-22
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write i…
- CVE-2026-4673HIGHCVSS 8.8EG 8.82026-03-24
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-4675HIGHCVSS 8.8EG 8.82026-03-24
Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →