CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 58 of 65
- CVE-2026-69447HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69449MEDIUMCVSS 6.7EG 6.72026-09-08
Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.
- CVE-2026-69455HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-69456HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-69459HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.
- CVE-2026-69462HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69463CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69468HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69469MEDIUMCVSS 6.6EG 6.62026-09-08
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-69476HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69477HIGHCVSS 7.3EG 7.32026-09-08
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
- CVE-2026-69478HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69479HIGHCVSS 8.4EG 8.42026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-69480HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69481HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69486HIGHCVSS 8.8EG 8.82026-09-15
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-69489HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69491CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
- CVE-2026-69492HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69493CRITICALCVSS 9.8EG 9.82026-09-08
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-69494HIGHCVSS 8.8EG 8.82026-09-08
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-69495HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-69496CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
- CVE-2026-69509HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69511HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69512HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69513HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2026-69514HIGHCVSS 7.5EG 7.52026-09-08
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
- CVE-2026-69518HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
- CVE-2026-69522HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-69529HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- CVE-2026-69535HIGHCVSS 7.8EG 7.82026-09-08
Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-69541HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69542HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.
- CVE-2026-69544HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-69547HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- CVE-2026-69548MEDIUMCVSS 4.6EG 4.62026-09-08
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
- CVE-2026-69556HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69563HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69564HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69566MEDIUMCVSS 6.8EG 6.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-69571HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69578HIGHCVSS 7.0EG 7.02026-09-08
Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-69580HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69583HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69586CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- CVE-2026-69589HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69590CRITICALCVSS 9.8EG 9.82026-09-08
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- CVE-2026-69592HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69593HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →