CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 51 of 65
- CVE-2026-50692HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-50696HIGHCVSS 7.5EG 7.52026-07-14
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
- CVE-2026-51218HIGHCVSS 7.5EG 7.52026-06-29
A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- CVE-2026-51219HIGHCVSS 7.5EG 7.52026-06-29
A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.
- CVE-2026-5185MEDIUMCVSS 5.3EG 5.32026-03-31
A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based buffer overfl…
- CVE-2026-5187CRITICALCVSS 9.8EG 9.82026-04-09
Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] and out[1]), enabling a 2-byte out-of-bo…
- CVE-2026-5201HIGHCVSS 7.5EG 7.52026-03-31
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacke…
- CVE-2026-5235MEDIUMCVSS 5.3EG 5.32026-03-31
A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation causes heap-based buffer overflow. The a…
- CVE-2026-5236MEDIUMCVSS 5.3EG 5.32026-03-31
A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of the argument n_presentations leads to hea…
- CVE-2026-5244HIGHCVSS 7.3EG 7.32026-04-02
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow…
- CVE-2026-5264CRITICALCVSS 9.8EG 9.82026-04-09
Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
- CVE-2026-5272HIGHCVSS 8.8EG 8.82026-04-01
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-52720HIGHCVSS 8.8EG 8.82026-06-15
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extend…
- CVE-2026-5275HIGHCVSS 8.8EG 8.82026-04-01
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-52834HIGHCVSS 7.3EG 7.32026-07-02
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid a…
- CVE-2026-53362CRITICALCVSS 7.8EG 9.0⚠ KEV2026-07-04
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), allocle…
- CVE-2026-53465MEDIUMCVSS 6.2EG 6.22026-06-10
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has be…
- CVE-2026-53720MEDIUMCVSS 5.1EG 5.12026-07-09
pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, the…
- CVE-2026-53938HIGHCVSS 8.2EG 8.22026-09-08
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does…
- CVE-2026-53994HIGHCVSS 6.5EG 7.52026-07-18
ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 …
- CVE-2026-54000HIGHCVSS 7.0EG 7.02026-07-10
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes tab…
- CVE-2026-54001HIGHCVSS 7.0EG 7.02026-07-10
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode …
- CVE-2026-5402HIGHCVSS 8.8EG 8.82026-04-30
TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
- CVE-2026-5403HIGHCVSS 7.8EG 7.82026-05-01
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
- CVE-2026-5405HIGHCVSS 7.8EG 7.82026-05-01
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
- CVE-2026-54109HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
- CVE-2026-54115HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
- CVE-2026-54122HIGHCVSS 8.4EG 8.42026-07-14
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
- CVE-2026-54124HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
- CVE-2026-54132MEDIUMCVSS 6.8EG 6.82026-07-14
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-54241HIGHCVSS 7.4EG 7.42026-09-11
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16…
- CVE-2026-5447HIGHCVSS 7.5EG 7.52026-04-09
Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate internally due to incorrect size handling of the AuthorityKeyIdentifier extension.
- CVE-2026-5448MEDIUMCVSS 4.3EG 4.32026-04-10
X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing date fields from a crafted X.509 certificate via the compatibility layer API. This is only triggered when calling these …
- CVE-2026-5450CRITICALCVSS 9.8EG 9.82026-04-20
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer over…
- CVE-2026-54559MEDIUMCVSS 6.9EG 6.92026-07-17
PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders …
- CVE-2026-54626CRITICALCVSS 9.8EG 9.82026-09-17
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte…
- CVE-2026-54627CRITICALCVSS 9.8EG 9.82026-09-17
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bi…
- CVE-2026-54696LOWCVSS 3.7EG 3.72026-06-30
Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::S…
- CVE-2026-54715HIGHCVSS 7.1EG 7.12026-07-30
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing versi…
- CVE-2026-5474HIGHCVSS 8.8EG 8.82026-04-03
A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-b…
- CVE-2026-54896LOWCVSS 2.1EG 2.12026-06-19
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in object mode, Oj.dump is vulnerable to a heap buffer overflow when serializing Exception objects with a large :indent va…
- CVE-2026-54984HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
- CVE-2026-54986HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-54987HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-54990CRITICALCVSS 8.8EG 9.82026-07-14
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-54992HIGHCVSS 7.8EG 8.42026-07-14
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
- CVE-2026-54993HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
- CVE-2026-55005HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-55010CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-55012HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →