CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,207 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 62 of 65
- CVE-2026-76918MEDIUMCVSS 5.5EG 5.52026-08-19
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-77102HIGHCVSS 7.5EG 7.52026-09-08
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- CVE-2026-77396MEDIUMCVSS 6.9EG 6.92026-09-18
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame b…
- CVE-2026-77481HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77482HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-77486HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-77495HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-77532CRITICALCVSS 9.6EG 9.62026-08-26
A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.
- CVE-2026-77652HIGHCVSS 7.8EG 7.82026-08-26
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When h…
- CVE-2026-77898HIGHCVSS 7.5EG 7.52026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-77904HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-77906HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-77907HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-78156HIGHCVSS 7.4EG 7.42026-08-23
A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulati…
- CVE-2026-78442HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-78447HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-78448HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-78456HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-78505HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-78509CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-78510CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78511HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78512HIGHCVSS 8.8EG 8.82026-09-08
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78517HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78521HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78526HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78689HIGHCVSS 8.1EG 8.12026-09-02
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configura…
- CVE-2026-78891HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78948CRITICALCVSS 9.6EG 9.62026-08-25
Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-7900HIGHCVSS 8.3EG 8.32026-05-06
Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79130CRITICALCVSS 9.6EG 9.62026-08-25
Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79142HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79216HIGHCVSS 7.5EG 7.52026-08-25
Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79231HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79377HIGHCVSS 7.5EG 7.52026-09-08
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
- CVE-2026-79393HIGHCVSS 7.5EG 7.52026-09-11
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to caus…
- CVE-2026-79591HIGHCVSS 7.8EG 7.82026-09-10
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
- CVE-2026-80074HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-80075HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
- CVE-2026-80077HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-80085HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-80087MEDIUMCVSS 6.5EG 6.52026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
- CVE-2026-8086MEDIUMCVSS 5.3EG 5.32026-05-07
A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The att…
- CVE-2026-8087MEDIUMCVSS 5.3EG 5.32026-05-07
A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow.…
- CVE-2026-81352HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
- CVE-2026-81353HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
- CVE-2026-81354HIGHCVSS 8.2EG 8.22026-09-08
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- CVE-2026-81355HIGHCVSS 7.5EG 7.52026-09-08
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
- CVE-2026-81386HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-81389HIGHCVSS 7.0EG 7.02026-09-08
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →