CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 59 of 65
- CVE-2026-69594HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69601HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69603HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-69604HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69621HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69623HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
- CVE-2026-69625HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69628HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.
- CVE-2026-69629HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-69638HIGHCVSS 8.4EG 8.42026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-69643HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69649HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-69669CRITICALCVSS 8.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.
- CVE-2026-69671HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69681HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69685HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-69688HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69691HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-69709HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-69715CRITICALCVSS 9.8EG 9.82026-09-08
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
- CVE-2026-69720HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- CVE-2026-69727HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69729HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.
- CVE-2026-69731HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69732HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
- CVE-2026-69738HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69758HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69764HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69768CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69769CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
- CVE-2026-69772HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.
- CVE-2026-69773HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69777HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-69778HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- CVE-2026-69786HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.
- CVE-2026-69787HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69790HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
- CVE-2026-69801HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69820HIGHCVSS 6.7EG 8.22026-09-08
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- CVE-2026-69822HIGHCVSS 7.8EG 7.82026-09-08
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-69824CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69826HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69829CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
- CVE-2026-69841HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69845CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-69847HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-69852HIGHCVSS 7.5EG 7.52026-09-08
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- CVE-2026-69860HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69875HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69878MEDIUMCVSS 6.4EG 6.42026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →