CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 2 of 66
- CVE-2026-21095CRITICALCVSS 9.8EG 9.82026-09-09
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
- CVE-2026-49921CRITICALCVSS 9.8EG 9.82026-09-08
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-69590CRITICALCVSS 9.8EG 9.82026-09-08
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- CVE-2026-72950CRITICALCVSS 9.8EG 9.82026-09-08
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- CVE-2026-69769CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
- CVE-2026-69829CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
- CVE-2026-69845CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-69824CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69768CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69715CRITICALCVSS 9.8EG 9.82026-09-08
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
- CVE-2026-69586CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- CVE-2026-69493CRITICALCVSS 9.8EG 9.82026-09-08
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-68839CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-67643CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-78509CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-69496CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
- CVE-2026-69463CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69491CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
- CVE-2026-69431CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-69408CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69276CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
- CVE-2026-67631CRITICALCVSS 9.8EG 9.82026-09-08
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2025-70293CRITICALCVSS 9.8EG 9.82026-08-26
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() whic…
- CVE-2026-76886CRITICALCVSS 9.8EG 9.82026-08-19
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-63633CRITICALCVSS 9.8EG 9.82026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM i…
- CVE-2026-55194CRITICALCVSS 9.8EG 9.82026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint ra…
- CVE-2026-55191CRITICALCVSS 9.8EG 9.82026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with …
- CVE-2026-75143CRITICALCVSS 9.8EG 9.82026-08-19
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buf…
- CVE-2026-58081CRITICALCVSS 9.8EG 9.82026-08-19
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from…
- CVE-2026-67868CRITICALCVSS 9.8EG 9.82026-08-17
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
- CVE-2026-65791CRITICALCVSS 9.8EG 9.82026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-67873CRITICALCVSS 9.8EG 9.82026-08-05
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does…
- CVE-2017-20241CRITICALCVSS 9.8EG 9.82026-08-04
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
- CVE-2026-67191CRITICALCVSS 9.8EG 9.82026-07-29
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A …
- CVE-2026-55971CRITICALCVSS 9.8EG 9.82026-07-27
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
- CVE-2026-56165CRITICALCVSS 9.8EG 9.82026-07-23
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
- CVE-2026-41252CRITICALCVSS 9.8EG 9.82026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map m…
- CVE-2026-13473CRITICALCVSS 9.8EG 9.82026-07-17
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and…
- CVE-2026-57090CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-56159CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-55010CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-50518CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-50447CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- CVE-2026-50330CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-49172CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-49164CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- CVE-2026-42990CRITICALCVSS 9.8EG 9.82026-07-14
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- CVE-2026-57156CRITICALCVSS 9.8EG 9.82026-07-10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled …
- CVE-2026-47291CRITICALCVSS 9.8EG 9.82026-06-09
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
- CVE-2026-45657CRITICALCVSS 9.8EG 9.82026-06-09
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →