CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 8 of 66
- CVE-2026-50380CRITICALCVSS 9.6EG 9.62026-07-14
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2026-13798CRITICALCVSS 9.6EG 9.62026-06-30
Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hig…
- CVE-2026-42904CRITICALCVSS 9.6EG 9.62026-06-09
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
- CVE-2026-6296CRITICALCVSS 9.6EG 9.62026-04-15
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2024-28231CRITICALCVSS 9.6EG 9.62024-03-20
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in…
- CVE-2023-4264CRITICALCVSS 9.6EG 9.62023-09-27
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
- CVE-2022-4920CRITICALCVSS 9.6EG 9.62023-07-29
Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve…
- CVE-2021-3966CRITICALCVSS 9.6EG 9.62023-01-11
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
- CVE-2021-3625CRITICALCVSS 9.6EG 9.62021-10-05
Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363
- CVE-2024-6246CRITICALCVSS 8.8EG 9.62024-11-22
Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentica…
- CVE-2025-24797CRITICALCVSS 9.4EG 9.42025-04-15
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentiall…
- CVE-2025-30216CRITICALCVSS 9.4EG 9.42025-03-25
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versi…
- CVE-2026-19313CRITICALCVSS 9.3EG 9.32026-08-27
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
- CVE-2025-34164CRITICALCVSS 9.3EG 9.32025-08-30
A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
- CVE-2025-54574CRITICALCVSS 9.3EG 9.32025-08-01
Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version…
- CVE-2014-0781HIGHCVSS v2 9.3EG 9.32014-03-14
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.
- CVE-2026-83632CRITICALCVSS 9.2EG 9.22026-10-02
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to ver…
- CVE-2026-91135CRITICALCVSS 9.2EG 9.22026-10-02
Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer with…
- CVE-2026-101283CRITICALCVSS 9.2EG 9.22026-09-30
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the …
- CVE-2026-19874CRITICALCVSS 9.1EG 9.12026-08-24
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers usi…
- CVE-2026-73242CRITICALCVSS 9.1EG 9.12026-08-11
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it…
- CVE-2026-15422CRITICALCVSS 9.1EG 9.12026-07-16
The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks…
- CVE-2026-56372CRITICALCVSS 9.1EG 9.12026-07-11
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposin…
- CVE-2026-49840CRITICALCVSS 9.1EG 9.12026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content…
- CVE-2026-34865CRITICALCVSS 9.1EG 9.12026-04-13
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- CVE-2026-4177CRITICALCVSS 9.1EG 9.12026-03-17
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation.…
- CVE-2026-26284CRITICALCVSS 9.1EG 9.12026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) file…
- CVE-2026-24679CRITICALCVSS 9.1EG 9.12026-02-09
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interfac…
- CVE-2025-62608CRITICALCVSS 9.1EG 9.12025-11-21
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds r…
- CVE-2025-58050CRITICALCVSS 9.1EG 9.12025-08-27
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handl…
- CVE-2025-23317CRITICALCVSS 9.1EG 9.12025-08-06
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code exe…
- CVE-2024-38160CRITICALCVSS 9.1EG 9.12024-08-13
Windows Network Virtualization Remote Code Execution Vulnerability
- CVE-2023-5841CRITICALCVSS 9.1EG 9.12024-02-01
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow…
- CVE-2023-5908CRITICALCVSS 9.1EG 9.12023-11-30
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
- CVE-2023-47455CRITICALCVSS 9.1EG 9.12023-11-07
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
- CVE-2022-2848CRITICALCVSS 9.1EG 9.12023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
- CVE-2022-31003CRITICALCVSS 9.1EG 9.12022-05-31
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An…
- CVE-2020-27263CRITICALCVSS 9.1EG 9.12021-01-14
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 an…
- CVE-2026-35547CRITICALCVSS 8.1EG 9.12026-04-30
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system…
- CVE-2026-44950CRITICALCVSS 9.0EG 9.02026-09-10
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does n…
- CVE-2025-20363CRITICALCVSS 9.0EG 9.02025-09-25
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow …
- CVE-2023-29125CRITICALCVSS 9.0EG 9.02024-11-05
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
- CVE-2024-37310CRITICALCVSS 9.0EG 9.02024-07-10
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and …
- CVE-2023-27882CRITICALCVSS 9.0EG 9.02023-11-14
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to…
- CVE-2023-25181CRITICALCVSS 9.0EG 9.02023-11-14
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packe…
- CVE-2023-27395CRITICALCVSS 9.0EG 9.02023-10-12
A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can…
- CVE-2022-2566CRITICALCVSS 9.0EG 9.02022-09-23
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead…
- CVE-2020-15205CRITICALCVSS 9.0EG 9.02020-09-25
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of …
- CVE-2020-6146CRITICALCVSS 8.8EG 9.02020-09-16
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application w…
- CVE-2025-8351CRITICALCVSS 7.8EG 9.02025-12-01
Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivir…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →