CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 54 of 65
- CVE-2026-61937HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-6210HIGHCVSS 8.7EG 8.72026-05-06
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* with…
- CVE-2026-62381MEDIUMCVSS 6.6EG 6.62026-08-22
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed …
- CVE-2026-62688HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- CVE-2026-62692HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-62695HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
- CVE-2026-62699MEDIUMCVSS 6.8EG 6.82026-08-11
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-62700HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-62710HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-62712HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-62713HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-62717HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
- CVE-2026-62719HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
- CVE-2026-62722HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-62732HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-62735HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-62736HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-62739HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-62741HIGHCVSS 7.8EG 7.82026-08-11
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-62744HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-62747HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-62752HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-62753HIGHCVSS 7.0EG 7.02026-08-11
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-62754HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-62758HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-62769MEDIUMCVSS 6.7EG 6.72026-08-11
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-62770HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-62771HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-62772HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-62781HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
- CVE-2026-62783HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-62784HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
- CVE-2026-62785HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- CVE-2026-62790HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- CVE-2026-62797HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-62799HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-62800HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- CVE-2026-62810HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-62811HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-62816HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-62822HIGHCVSS 8.8EG 8.82026-08-11
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2026-62823HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-62871HIGHCVSS 7.8EG 7.82026-08-11
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-62881MEDIUMCVSS 6.7EG 6.72026-08-11
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-62883MEDIUMCVSS 6.7EG 6.72026-08-11
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-62885HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-62886HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-62890HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
- CVE-2026-62894HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2026-62913HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →