CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 28 of 66
- CVE-2026-69731HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69801HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69738HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69841HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69709HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-69685HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-69720HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- CVE-2026-69592HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69542HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.
- CVE-2026-69535HIGHCVSS 7.8EG 7.82026-09-08
Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-69571HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69509HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69480HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69478HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69459HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.
- CVE-2026-69456HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-69444HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-69433HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2026-69447HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69424HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69421HIGHCVSS 7.8EG 7.82026-09-08
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69348HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-69283HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69284HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-69270HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-68888HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68885HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68850HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
- CVE-2026-68848HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-62810HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-83976HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83975HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83974HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83988HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83969HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83986HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83955HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83952HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-81355HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
- CVE-2026-80075HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
- CVE-2026-77904HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69787HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69476HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69604HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69580HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69589HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69583HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69544HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-69293HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-68877HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →