CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 61 of 65
- CVE-2026-72990HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72991HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72992HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72993HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72994HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72995HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72996HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-72997HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73000HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73001HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73007HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73011HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73012HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
- CVE-2026-73013HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-73015HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73016HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-73017HIGHCVSS 7.5EG 7.52026-09-08
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
- CVE-2026-73018HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- CVE-2026-73020HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73021HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73023HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-73024HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-73026HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-73072HIGHCVSS 8.5EG 8.52026-08-11
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOF…
- CVE-2026-7310MEDIUMCVSS 4.4EG 4.42026-05-26
A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corru…
- CVE-2026-73242HIGHCVSS 8.3EG 8.32026-08-11
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it…
- CVE-2026-7339HIGHCVSS 8.8EG 8.82026-04-28
Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-7353HIGHCVSS 8.3EG 8.32026-04-28
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-7378MEDIUMCVSS 5.5EG 5.52026-04-30
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CVE-2026-75141HIGHCVSS 7.8EG 7.82026-08-19
FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a…
- CVE-2026-75143CRITICALCVSS 9.8EG 9.82026-08-19
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buf…
- CVE-2026-75144HIGHCVSS 7.8EG 7.82026-08-19
FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packeti…
- CVE-2026-75538HIGHCVSS 8.2EG 8.22026-09-01
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up…
- CVE-2026-75619MEDIUMCVSS 5.7EG 5.72026-08-19
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bo…
- CVE-2026-75750HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op…
- CVE-2026-75766HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op…
- CVE-2026-75767HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op…
- CVE-2026-75769HIGHCVSS 7.8EG 7.82026-08-25
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op…
- CVE-2026-75883MEDIUMCVSS 6.8EG 6.82026-09-18
The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing…
- CVE-2026-75893UnratedEG not assessed2026-09-18
In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths.
- CVE-2026-76022HIGHCVSS 8.8EG 8.82026-08-20
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-76034HIGHCVSS 8.8EG 8.82026-08-18
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-76036CRITICALCVSS 9.6EG 9.62026-08-18
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-76046HIGHCVSS 8.3EG 8.32026-08-18
Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security se…
- CVE-2026-76883MEDIUMCVSS 5.5EG 5.52026-08-19
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76886CRITICALCVSS 9.8EG 9.82026-08-19
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76887MEDIUMCVSS 6.5EG 6.52026-08-19
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76888HIGHCVSS 7.5EG 7.52026-08-19
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76889MEDIUMCVSS 5.5EG 5.52026-08-19
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76917MEDIUMCVSS 5.5EG 5.52026-08-19
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →