CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 53 of 65
- CVE-2026-56967HIGHCVSS 8.0EG 8.02026-09-15
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2026-57087HIGHCVSS 7.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-57090CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-57094HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-57096HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-57156CRITICALCVSS 9.8EG 9.82026-07-10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled …
- CVE-2026-57164MEDIUMCVSS 5.9EG 5.92026-09-04
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applicat…
- CVE-2026-57226LOWCVSS 3.7EG 3.72026-09-18
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompress…
- CVE-2026-58081CRITICALCVSS 9.8EG 9.82026-08-19
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from…
- CVE-2026-58095HIGHCVSS 8.8EG 8.82026-08-26
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially exe…
- CVE-2026-58097HIGHCVSS 7.8EG 7.82026-08-26
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially exe…
- CVE-2026-58264CRITICALCVSS 9.8EG 9.82026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value …
- CVE-2026-58306MEDIUMCVSS 6.1EG 6.12026-07-09
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.
- CVE-2026-58379HIGHCVSS 7.3EG 7.32026-07-03
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially…
- CVE-2026-58471MEDIUMCVSS 5.9EG 5.92026-07-07
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename r…
- CVE-2026-58530HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
- CVE-2026-58534HIGHCVSS 7.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
- CVE-2026-58538HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-58542HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
- CVE-2026-58547HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
- CVE-2026-5858HIGHCVSS 8.8EG 8.82026-04-08
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-58599HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
- CVE-2026-58600HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-58601HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-58610HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
- CVE-2026-58618HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-5864MEDIUMCVSS 4.3EG 6.52026-04-08
Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-58640HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-58651HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-5867MEDIUMCVSS 4.3EG 6.52026-04-08
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-58679HIGHCVSS 8.4EG 8.42026-09-15
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-5868HIGHCVSS 8.8EG 8.82026-04-08
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-5869MEDIUMCVSS 4.3EG 6.52026-04-08
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-58820HIGHCVSS 7.8EG 7.82026-09-08
In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.
- CVE-2026-59134HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-59186HIGHCVSS 7.1EG 7.12026-08-25
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a he…
- CVE-2026-59187HIGHCVSS 7.1EG 7.12026-08-25
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write whe…
- CVE-2026-61353HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-61355HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-61359HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
- CVE-2026-61363HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-61368MEDIUMCVSS 5.5EG 5.52026-08-11
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
- CVE-2026-61390HIGHCVSS 7.7EG 7.72026-07-22
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
- CVE-2026-61464LOWCVSS 1.8EG 1.82026-07-15
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.
- CVE-2026-61714HIGHCVSS 7.8EG 7.82026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap a…
- CVE-2026-61721HIGHCVSS 8.0EG 8.02026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validat…
- CVE-2026-61923HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-61926HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-61930HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-61932HIGHCVSS 7.8EG 7.82026-08-11
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →