CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

1,970 vulnerabilities with CWE-122
CVE-2026-3713 MEDIUM
libpng <=1.6.55 - Buffer Overflow
CVSS 5.3
CVE-2026-28546 MEDIUM
Scanning Module - Buffer Overflow
CVSS 5.9
CVE-2026-3544 HIGH
Google Chrome <145.0.7632.159 - Buffer Overflow
CVSS 8.8
CVE-2026-20053 MEDIUM
Cisco Snort 3 - Memory Corruption
CVSS 5.8
CVE-2026-29022 HIGH
dr_libs <=0.14.4 - Memory Corruption
CVSS 7.3
CVE-2026-22891 CRITICAL
libbiosig 3.9.2 - Buffer Overflow
CVSS 9.8
CVE-2026-20777 HIGH
The Biosig Project libbiosig 3.9.2 - Buffer Overflow
CVSS 8.1
CVE-2026-3463 LOW
xlnt-community xlnt <=1.6.1 - Buffer Overflow
CVSS 3.3
CVE-2026-0006 CRITICAL
Unknown Product - Buffer Overflow
CVSS 9.8
CVE-2026-3407 LOW
YosysHQ yosys <=0.62 - Buffer Overflow
CVSS 3.3
CVE-2026-3393 LOW
jarikomppa soloud <20200207 - Buffer Overflow
CVSS 3.3
CVE-2026-28421 MEDIUM
Vim <9.2.0077 - Memory Corruption
CVSS 5.3
CVE-2026-28420 MEDIUM
Vim <9.2.0076 - Buffer Overflow
CVSS 4.4
CVE-2026-28418 MEDIUM
Vim <9.2.0074 - Buffer Overflow
CVSS 4.4
CVE-2026-3281 MEDIUM
libvips 8.19.0 - Buffer Overflow
CVSS 5.3
CVE-2026-2597 HIGH
Crypt::SysRandom::XS <0.010 - Buffer Overflow
CVSS 7.5
CVE-2026-23750 HIGH
Golioth Pouch 0.1.0 - Buffer Overflow
CVSS 8.1
CVE-2026-27799 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 4.0
CVE-2026-3147 MEDIUM
libvips <=8.18.0 - Buffer Overflow
CVSS 5.3
CVE-2026-26284 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25897 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25794 HIGH
ImageMagick <7.1.2-15 - Memory Corruption
CVSS 8.2
CVE-2026-25576 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 5.1
CVE-2025-69247 HIGH
free5GC go-upf <1.2.8 - Buffer Overflow
CVSS 7.5
CVE-2025-14905 HIGH
389-ds-base - Memory Corruption
CVSS 7.2
Details
Vulnerabilities 1,970
Exploit Likelihood High