CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 57 of 65
- CVE-2026-68889HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68890HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68892HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68894HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68897HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-69242HIGHCVSS 8.4EG 8.42026-08-20
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflo…
- CVE-2026-69270HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69271HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69272HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69276CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
- CVE-2026-69283HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69284HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-69285HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-69291HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-69293HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69307HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69313HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69323HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69325HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
- CVE-2026-69334HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-69336HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69340HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69346HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69347HIGHCVSS 7.4EG 7.42026-09-08
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- CVE-2026-69348HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-69350MEDIUMCVSS 6.7EG 6.72026-09-08
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-69352HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69359HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-69360HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69368HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-69371HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69386HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69389HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- CVE-2026-69394HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69408CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69418HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69420HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.
- CVE-2026-69421HIGHCVSS 7.8EG 7.82026-09-08
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69423HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69424HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69426HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
- CVE-2026-69429HIGHCVSS 7.5EG 7.52026-09-08
Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.
- CVE-2026-69431CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-69432HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69433HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2026-69434HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.
- CVE-2026-69436HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2026-69439HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-69442HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-69444HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →