CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 25 of 66
- CVE-2026-61721HIGHCVSS 8.0EG 8.02026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validat…
- CVE-2026-56967HIGHCVSS 8.0EG 8.02026-09-15
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2026-42807HIGHCVSS 8.0EG 8.02026-09-10
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. …
- CVE-2026-28662HIGHCVSS 8.0EG 8.02026-09-08
In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User in…
- CVE-2026-69777HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-69847HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-69773HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69826HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69727HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69643HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69462HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69346HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68894HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68876HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68880HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- CVE-2026-68827HIGHCVSS 8.0EG 8.02026-09-08
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69875HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69623HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
- CVE-2026-69481HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69423HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69418HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69371HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69271HIGHCVSS 8.0EG 8.02026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-18282HIGHCVSS 8.0EG 8.02026-08-20
Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. A…
- CVE-2026-18281HIGHCVSS 8.0EG 8.02026-08-20
Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attac…
- CVE-2026-50683HIGHCVSS 8.0EG 8.02026-07-14
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-0059HIGHCVSS 8.0EG 8.02026-06-01
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User i…
- CVE-2026-20452HIGHCVSS 8.0EG 8.02026-06-01
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2026-8834HIGHCVSS 8.0EG 8.02026-05-26
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.
- CVE-2026-3561HIGHCVSS 8.0EG 8.02026-03-16
Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Altho…
- CVE-2026-3557HIGHCVSS 8.0EG 8.02026-03-16
Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips …
- CVE-2026-3555HIGHCVSS 8.0EG 8.02026-03-16
Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue …
- CVE-2026-25173HIGHCVSS 8.0EG 8.02026-03-10
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-62673HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing …
- CVE-2025-62405HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet con…
- CVE-2025-62404HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet who…
- CVE-2025-61983HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet con…
- CVE-2025-61944HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet con…
- CVE-2025-59487HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The vulnerability arises from improper va…
- CVE-2025-59482HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet con…
- CVE-2025-58455HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet who…
- CVE-2025-58077HIGHCVSS 8.0EG 8.02026-02-03
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted set of network p…
- CVE-2025-36923HIGHCVSS 8.0EG 8.02025-12-11
In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution pr…
- CVE-2025-62452HIGHCVSS 8.0EG 8.02025-11-11
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-60715HIGHCVSS 8.0EG 8.02025-11-11
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-20742HIGHCVSS 8.0EG 8.02025-11-04
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2025-53720HIGHCVSS 8.0EG 8.02025-08-12
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-50164HIGHCVSS 8.0EG 8.02025-08-12
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-50162HIGHCVSS 8.0EG 8.02025-08-12
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- CVE-2025-50160HIGHCVSS 8.0EG 8.02025-08-12
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →