CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 56 of 65
- CVE-2026-67373HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67380HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67381HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-67384HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67388HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67549HIGHCVSS 7.6EG 7.62026-09-18
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so calle…
- CVE-2026-67631CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-67638HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67639HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67642HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67643CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-67860HIGHCVSS 7.5EG 7.52026-08-04
open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
- CVE-2026-67867HIGHCVSS 7.5EG 7.52026-08-05
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data
- CVE-2026-67868CRITICALCVSS 9.8EG 9.82026-08-17
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
- CVE-2026-67873CRITICALCVSS 9.8EG 9.82026-08-05
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does…
- CVE-2026-6846HIGHCVSS 7.8EG 7.82026-04-22
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this m…
- CVE-2026-68513HIGHCVSS 7.1EG 7.12026-08-25
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by…
- CVE-2026-68514MEDIUMCVSS 5.5EG 5.52026-08-25
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap ou…
- CVE-2026-68515HIGHCVSS 7.1EG 7.12026-08-25
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap a…
- CVE-2026-68580HIGHCVSS 7.5EG 7.52026-08-02
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attacker…
- CVE-2026-68765MEDIUMCVSS 6.1EG 6.12026-08-17
hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field tok…
- CVE-2026-68775HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68785MEDIUMCVSS 4.9EG 4.92026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68786HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68787HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
- CVE-2026-68794HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68796HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68798HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68800HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68801HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68804HIGHCVSS 7.8EG 7.82026-08-11
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68805HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68807HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68812HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68815HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-68827HIGHCVSS 8.0EG 8.02026-09-08
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68828HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-68833MEDIUMCVSS 6.8EG 6.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-68839CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-68841HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68844HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
- CVE-2026-68845HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-68848HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-68850HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
- CVE-2026-68876HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68877HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
- CVE-2026-68880HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68884HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-68885HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68888HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →