CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 48 of 52
- CVE-2026-49175HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-49178HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- CVE-2026-49184HIGHCVSS 7.8EG 8.42026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-49790HIGHCVSS 7.8EG 7.82026-07-14
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- CVE-2026-49793HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
- CVE-2026-49796HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
- CVE-2026-49797HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-49800HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
- CVE-2026-49804MEDIUMCVSS 6.6EG 6.62026-07-14
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-49840CRITICALCVSS 9.1EG 9.12026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content…
- CVE-2026-49841CRITICALCVSS 9.8EG 9.82026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request hand…
- CVE-2026-50012MEDIUMCVSS 5.5EG 5.52026-07-16
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's …
- CVE-2026-50299MEDIUMCVSS 6.8EG 6.82026-07-14
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-50301HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-50308HIGHCVSS 7.8EG 7.82026-07-14
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50309HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-50313HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50327HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
- CVE-2026-50330CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50332HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50336HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
- CVE-2026-50347HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
- CVE-2026-50362HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
- CVE-2026-50363HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-50370HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-50372HIGHCVSS 7.0EG 7.02026-07-14
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
- CVE-2026-50375HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2026-50380CRITICALCVSS 9.6EG 9.62026-07-14
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2026-50386HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50407HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-50417HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-50447CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- CVE-2026-50448HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50461HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50471HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50477HIGHCVSS 7.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50480HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
- CVE-2026-50482HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-50484HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50489HIGHCVSS 7.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-50492MEDIUMCVSS 6.8EG 6.82026-07-14
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-50494HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-50499HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-50518CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-50655HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
- CVE-2026-50668MEDIUMCVSS 6.8EG 6.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-50670HIGHCVSS 8.8EG 8.82026-07-14
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50675HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-50678MEDIUMCVSS 6.6EG 6.62026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-50679HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →