CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 10 of 66
- CVE-2026-69334HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-69291HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-72960HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
- CVE-2026-72959HIGHCVSS 8.8EG 8.82026-09-08
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- CVE-2026-72933HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.
- CVE-2026-69625HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69547HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- CVE-2026-69512HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69511HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69434HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.
- CVE-2026-69386HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69360HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-68828HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-68775HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67642HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67639HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67638HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67388HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67381HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-67380HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-85877HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
- CVE-2026-83998HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-83996HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2026-72940HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.
- CVE-2026-80077HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-80074HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-68786HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-78517HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-78505HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-78511HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-67384HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77907HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-69285HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- CVE-2026-72986HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
- CVE-2026-77495HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69778HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- CVE-2026-69764HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69529HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- CVE-2026-69671HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69649HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-69603HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-69556HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-69518HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
- CVE-2026-70586HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.
- CVE-2026-70351HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-69860HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69772HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.
- CVE-2026-69681HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69729HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.
- CVE-2026-69628HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →