CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 55 of 65
- CVE-2026-6296CRITICALCVSS 9.6EG 9.62026-04-15
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-6298MEDIUMCVSS 4.3EG 4.32026-04-15
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-6305HIGHCVSS 8.8EG 8.82026-04-15
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-6306HIGHCVSS 8.8EG 8.82026-04-15
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-63090HIGHCVSS 8.8EG 8.82026-07-20
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments e…
- CVE-2026-63422HIGHCVSS 7.8EG 7.82026-09-18
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of …
- CVE-2026-63451LOWCVSS 3.3EG 3.32026-09-18
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, a locally supplied detection rule that combines frame inspection without content and a transforme…
- CVE-2026-63513HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-63518HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-63519HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-63532HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-63533HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-6361HIGHCVSS 8.3EG 8.32026-04-15
Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromiu…
- CVE-2026-63633HIGHCVSS 7.7EG 7.72026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM i…
- CVE-2026-64620CRITICALCVSS 9.1EG 9.82026-07-20
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and …
- CVE-2026-64830HIGHCVSS 8.8EG 8.82026-07-22
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct s…
- CVE-2026-64898HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-64903HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-64906HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-64908HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-64909HIGHCVSS 7.8EG 7.82026-08-11
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-6491MEDIUMCVSS 5.3EG 5.32026-04-17
A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to…
- CVE-2026-64911HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-64914HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-64915HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-64920HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2026-6529MEDIUMCVSS 5.5EG 5.52026-04-30
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CVE-2026-6530MEDIUMCVSS 5.5EG 5.52026-04-30
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CVE-2026-65661HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-65664HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-65671HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
- CVE-2026-65672HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
- CVE-2026-65679HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-65774HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-65786HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-65787HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-65790HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
- CVE-2026-65791CRITICALCVSS 9.8EG 9.82026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-65796HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-65797MEDIUMCVSS 6.7EG 6.72026-08-11
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-65799HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-65814HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-66035HIGHCVSS 7.5EG 7.52026-07-24
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length…
- CVE-2026-66036HIGHCVSS 8.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between fra…
- CVE-2026-66039HIGHCVSS 7.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value…
- CVE-2026-66040HIGHCVSS 8.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf…
- CVE-2026-66799HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
- CVE-2026-66810MEDIUMCVSS 5.5EG 5.52026-08-11
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-67191CRITICALCVSS 9.8EG 9.82026-07-29
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A …
- CVE-2026-67305HIGHCVSS 8.8EG 8.82026-08-01
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buf…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →