CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 1 of 66
- CVE-2026-94127CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-22
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Autho…
- CVE-2025-25249CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-13
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, …
- CVE-2024-38812CRITICALCVSS 9.8EG 9.8⚠ KEV2024-09-17
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet …
- CVE-2024-37079CRITICALCVSS 9.8EG 9.8⚠ KEV2024-06-18
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potent…
- CVE-2023-27997CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-13
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version …
- CVE-2019-3568CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-14
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business f…
- CVE-2015-3113CRITICALCVSS 9.8EG 9.8⚠ KEV2015-06-23
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as e…
- CVE-2020-16010CRITICALCVSS 9.6EG 9.6⚠ KEV2020-11-03
Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2021-21017CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-11
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vul…
- CVE-2009-3459CRITICALCVSS 8.8EG 9.0⚠ KEV2009-10-13
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wil…
- CVE-2026-85880CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
- CVE-2026-53362CRITICALCVSS 7.8EG 9.0⚠ KEV2026-07-04
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), allocle…
- CVE-2025-24993CRITICALCVSS 7.8EG 9.0⚠ KEV2025-03-11
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2025-24985CRITICALCVSS 7.8EG 9.0⚠ KEV2025-03-11
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- CVE-2025-21418CRITICALCVSS 7.8EG 9.0⚠ KEV2025-02-11
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2025-21333CRITICALCVSS 7.8EG 9.0⚠ KEV2025-01-14
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- CVE-2024-49138CRITICALCVSS 7.8EG 9.0⚠ KEV2024-12-12
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2024-30051CRITICALCVSS 7.8EG 9.0⚠ KEV2024-05-14
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2023-36036CRITICALCVSS 7.8EG 9.0⚠ KEV2023-11-14
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2023-4911CRITICALCVSS 7.8EG 9.0⚠ KEV2023-10-03
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables …
- CVE-2023-28252CRITICALCVSS 7.8EG 9.0⚠ KEV2023-04-11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-23376CRITICALCVSS 7.8EG 9.0⚠ KEV2023-02-14
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2026-10747CRITICALCVSS 10.0EG 10.02026-09-18
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
- CVE-2026-46752CRITICALCVSS 10.0EG 10.02026-06-25
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
- CVE-2026-24822CRITICALCVSS 10.0EG 10.02026-01-27
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.
- CVE-2025-23123CRITICALCVSS 10.0EG 10.02025-05-19
A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow vulnerability in the UniFi Protect Cameras (Version 4.75.43 and earlier) firmware.
- CVE-2023-45318CRITICALCVSS 10.0EG 10.02024-02-20
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious pac…
- CVE-2022-34819CRITICALCVSS 10.0EG 10.02022-07-12
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC…
- CVE-2021-21940CRITICALCVSS 10.0EG 10.02021-10-12
A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious pac…
- CVE-2021-34770CRITICALCVSS 10.0EG 10.02021-09-23
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute …
- CVE-2021-25387CRITICALCVSS 9.0EG 10.02021-06-11
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
- CVE-2026-10858CRITICALCVSS 9.9EG 9.92026-09-18
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
- CVE-2026-44050CRITICALCVSS 9.9EG 9.92026-05-21
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.
- CVE-2026-32710CRITICALCVSS 9.9EG 9.92026-03-20
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possi…
- CVE-2016-9603CRITICALCVSS 5.5EG 9.92018-07-27
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A…
- CVE-2026-14269CRITICALCVSS 9.8EG 9.82026-10-08
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote…
- CVE-2026-76471CRITICALCVSS 9.8EG 9.82026-10-07
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The v…
- CVE-2016-15059CRITICALCVSS 9.8EG 9.82026-09-22
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized fr…
- CVE-2026-58264CRITICALCVSS 9.8EG 9.82026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value …
- CVE-2026-54627CRITICALCVSS 9.8EG 9.82026-09-17
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bi…
- CVE-2026-54626CRITICALCVSS 9.8EG 9.82026-09-17
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte…
- CVE-2026-91106CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-91105CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-91104CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-91098CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-82717CRITICALCVSS 9.8EG 9.82026-09-16
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when …
- CVE-2026-81642CRITICALCVSS 9.8EG 9.82026-09-16
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression poin…
- CVE-2026-39919CRITICALCVSS 9.8EG 9.82026-09-15
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image …
- CVE-2026-85103CRITICALCVSS 9.8EG 9.82026-09-09
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
- CVE-2026-21096CRITICALCVSS 9.8EG 9.82026-09-09
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →