CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 23 of 66
- CVE-2026-72962HIGHCVSS 8.2EG 8.22026-09-08
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-75538HIGHCVSS 8.2EG 8.22026-09-01
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up…
- CVE-2026-47652HIGHCVSS 8.2EG 8.22026-06-09
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-32316HIGHCVSS 8.2EG 8.22026-04-13
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_bad functions, where concatenating strings with a combined length exceeding 2^31…
- CVE-2026-27654HIGHCVSS 8.2EG 8.22026-03-24
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker…
- CVE-2026-25794HIGHCVSS 8.2EG 8.22026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are…
- CVE-2026-2007HIGHCVSS 8.2EG 8.22026-02-12
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of att…
- CVE-2025-61553HIGHCVSS 8.2EG 8.22025-10-16
An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration…
- CVE-2025-32990HIGHCVSS 8.2EG 8.22025-07-10
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB)…
- CVE-2025-1943HIGHCVSS 8.2EG 8.22025-03-04
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability…
- CVE-2023-31276HIGHCVSS 8.2EG 8.22025-02-12
Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP bef…
- CVE-2025-0611HIGHCVSS 8.2EG 8.22025-01-22
Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-30259HIGHCVSS 8.2EG 8.22024-05-14
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflo…
- CVE-2023-6779HIGHCVSS 8.2EG 8.22024-01-31
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigge…
- CVE-2023-39947HIGHCVSS 8.2EG 8.22023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` par…
- CVE-2023-39946HIGHCVSS 8.2EG 8.22023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that …
- CVE-2022-2809HIGHCVSS 8.2EG 8.22022-10-27
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how…
- CVE-2021-3861HIGHCVSS 8.2EG 8.22022-02-07
The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hv…
- CVE-2021-3835HIGHCVSS 8.2EG 8.22022-02-07
Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf
- CVE-2021-31429HIGHCVSS 8.2EG 8.22021-04-29
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to …
- CVE-2021-31428HIGHCVSS 8.2EG 8.22021-04-29
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to …
- CVE-2026-50680HIGHCVSS 7.8EG 8.22026-07-14
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2019-5436HIGHCVSS 7.8EG 8.22019-05-28
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
- CVE-2026-69820HIGHCVSS 6.7EG 8.22026-09-08
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
- CVE-2024-6154HIGHCVSS 6.7EG 8.22024-06-20
Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain …
- CVE-2026-14888HIGHCVSS 8.1EG 8.12026-10-08
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
- CVE-2026-46570HIGHCVSS 8.1EG 8.12026-10-07
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is tr…
- CVE-2026-14316HIGHCVSS 8.1EG 8.12026-10-01
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of t…
- CVE-2026-95389HIGHCVSS 8.1EG 8.12026-09-29
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-11727HIGHCVSS 8.1EG 8.12026-09-18
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy…
- CVE-2026-69786HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.
- CVE-2026-69732HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
- CVE-2026-69325HIGHCVSS 8.1EG 8.12026-09-08
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
- CVE-2026-78689HIGHCVSS 8.1EG 8.12026-09-02
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configura…
- CVE-2026-19004HIGHCVSS 8.1EG 8.12026-08-12
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database se…
- CVE-2026-71331HIGHCVSS 8.1EG 8.12026-08-11
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
- CVE-2026-65796HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-65679HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- CVE-2026-62781HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
- CVE-2026-61363HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-59134HIGHCVSS 8.1EG 8.12026-08-11
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-48440HIGHCVSS 8.1EG 8.12026-08-11
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue …
- CVE-2026-20465HIGHCVSS 8.1EG 8.12026-08-03
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2026-49035HIGHCVSS 8.1EG 8.12026-07-23
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurati…
- CVE-2026-13072HIGHCVSS 8.1EG 8.12026-07-22
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or oth…
- CVE-2026-42533HIGHCVSS 8.1EG 8.12026-07-15
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same r…
- CVE-2026-56123HIGHCVSS 8.1EG 8.12026-06-25
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. Dur…
- CVE-2026-2467HIGHCVSS 8.1EG 8.12026-06-17
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*,…
- CVE-2026-42055HIGHCVSS 8.1EG 8.12026-06-17
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic…
- CVE-2026-48131HIGHCVSS 8.1EG 8.12026-05-26
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →