CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 52 of 65
- CVE-2026-55017HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55029HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55033HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55037HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55039HIGHCVSS 7.8EG 7.82026-07-14
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55041HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55043HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2026-55048HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55049HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55053HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55056HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55120HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2026-55123HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2026-55125HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55127HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55129HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55130HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55131HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55133HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
- CVE-2026-55137HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55140HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55191HIGHCVSS 8.7EG 8.72026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with …
- CVE-2026-55193HIGHCVSS 8.7EG 8.72026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte Re…
- CVE-2026-55194HIGHCVSS 8.7EG 8.72026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint ra…
- CVE-2026-55294HIGHCVSS 7.8EG 7.82026-09-08
In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-55323HIGHCVSS 7.8EG 7.82026-09-15
In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…
- CVE-2026-55556HIGHCVSS 8.2EG 8.22026-09-18
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic A…
- CVE-2026-55893HIGHCVSS 7.3EG 7.32026-08-20
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking t…
- CVE-2026-55947HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-55971CRITICALCVSS 9.8EG 9.82026-07-27
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
- CVE-2026-55999HIGHCVSS 7.8EG 8.52026-07-08
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
- CVE-2026-56001HIGHCVSS 8.8EG 8.82026-07-08
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
- CVE-2026-56002HIGHCVSS 8.8EG 8.82026-07-08
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server.
- CVE-2026-56003HIGHCVSS 8.8EG 8.82026-07-08
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code…
- CVE-2026-56123HIGHCVSS 8.1EG 8.12026-06-25
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. Dur…
- CVE-2026-56135HIGHCVSS 7.4EG 7.42026-08-24
In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS ima…
- CVE-2026-56156HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-56159CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-56165CRITICALCVSS 9.8EG 9.82026-07-23
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
- CVE-2026-56175HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-56182HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-56189HIGHCVSS 8.4EG 8.42026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
- CVE-2026-56194HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
- CVE-2026-56208HIGHCVSS 7.6EG 7.62026-06-19
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_…
- CVE-2026-56372CRITICALCVSS 9.1EG 9.12026-07-11
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposin…
- CVE-2026-56392MEDIUMCVSS 6.1EG 6.12026-07-24
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, …
- CVE-2026-5653MEDIUMCVSS 5.5EG 5.52026-04-30
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CVE-2026-56645HIGHCVSS 8.8EG 8.82026-07-03
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-56650HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-56789MEDIUMCVSS 6.5EG 6.52026-06-25
RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger memory corruption by failing to clamp satellite count values from RINEX epoch headers. Attackers…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →