CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 11 of 66
- CVE-2026-69495HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-69494HIGHCVSS 8.8EG 8.82026-09-08
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-67373HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77482HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-69522HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-62744HIGHCVSS 8.8EG 8.82026-09-08
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-18341HIGHCVSS 8.8EG 8.82026-09-04
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
- CVE-2026-84268HIGHCVSS 8.8EG 8.82026-09-01
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the serv…
- CVE-2026-58095HIGHCVSS 8.8EG 8.82026-08-26
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially exe…
- CVE-2026-79231HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78891HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79142HIGHCVSS 8.8EG 8.82026-08-25
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-50538HIGHCVSS 8.8EG 8.82026-08-21
LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its…
- CVE-2026-76022HIGHCVSS 8.8EG 8.82026-08-20
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-55193HIGHCVSS 8.8EG 8.82026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte Re…
- CVE-2026-76034HIGHCVSS 8.8EG 8.82026-08-18
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-19385HIGHCVSS 8.8EG 8.82026-08-13
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17…
- CVE-2026-14676HIGHCVSS 8.8EG 8.82026-08-13
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor vers…
- CVE-2026-14670HIGHCVSS 8.8EG 8.82026-08-13
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16…
- CVE-2026-14669HIGHCVSS 8.8EG 8.82026-08-13
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL…
- CVE-2026-14664HIGHCVSS 8.8EG 8.82026-08-13
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but …
- CVE-2026-62822HIGHCVSS 8.8EG 8.82026-08-11
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2026-62823HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-62790HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- CVE-2026-62800HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- CVE-2026-62913HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-62816HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-62784HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
- CVE-2026-62785HIGHCVSS 8.8EG 8.82026-08-11
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- CVE-2026-67305HIGHCVSS 8.8EG 8.82026-08-01
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buf…
- CVE-2026-17951HIGHCVSS 8.8EG 8.82026-07-30
Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-17935HIGHCVSS 8.8EG 8.82026-07-30
Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-66040HIGHCVSS 8.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf…
- CVE-2026-66036HIGHCVSS 8.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between fra…
- CVE-2026-64830HIGHCVSS 8.8EG 8.82026-07-22
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct s…
- CVE-2026-8987HIGHCVSS 8.8EG 8.82026-07-21
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service a…
- CVE-2026-44178HIGHCVSS 8.8EG 8.82026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the …
- CVE-2026-63090HIGHCVSS 8.8EG 8.82026-07-20
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments e…
- CVE-2026-11826HIGHCVSS 8.8EG 8.82026-07-18
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In …
- CVE-2026-15767HIGHCVSS 8.8EG 8.82026-07-14
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
- CVE-2026-57094HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-56194HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50692HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-50670HIGHCVSS 8.8EG 8.82026-07-14
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50370HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-49178HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- CVE-2026-48564HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- CVE-2026-55005HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-42975HIGHCVSS 8.8EG 8.82026-07-14
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-15123HIGHCVSS 8.8EG 8.82026-07-08
Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →