CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-5403 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-5405 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-35547
Heap overflow in libnv
CVE-2026-42512
Remotely triggerable out-of-bounds heap write in dhclient
CVE-2026-6530 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-6529 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-5653 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-5402 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 8.8
CVE-2026-7378 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-7353 HIGH
Google Chrome < 147.0.7727.138 - Buffer Overflow
CVSS 8.3
CVE-2026-7339 HIGH
Google Chrome < 147.0.7727.138 - Buffer Overflow
CVSS 8.8
CVE-2026-20766 HIGH
Milesight Cameras Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-7040 HIGH
Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters
CVSS 7.5
CVE-2026-33602 MEDIUM
Off-by-one access when processing crafted UDP responses
CVSS 6.5
CVE-2026-6846 HIGH
Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVSS 7.8
CVE-2026-40706 HIGH
Tuxera NTFS-3G < 2026.2.25 - Buffer Overflow
CVSS 8.4
CVE-2026-40614 HIGH
PJSIP: Heap buffer overflow in Opus codec decoding
CVSS 8.8
CVE-2026-5450 CRITICAL
THE GNU C Library Glibc < 2.7 - Buffer Overflow
CVSS 9.8
CVE-2026-32135 HIGH
NanoMQ has Heap Buffer Overflow in URI Parameter Parsing
CVSS 7.5
CVE-2026-41445 HIGH
KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()
CVSS 8.8
CVE-2026-32961 MEDIUM
Silex Technology, Inc. SD-330AC - Buffer Overflow
CVSS 5.3
CVE-2026-32956 CRITICAL
Silex Technology, Inc. SD-330AC - Buffer Overflow
CVSS 9.8
CVE-2026-35512 HIGH
xrdp: Heap buffer overflow in EGFX channel
CVSS 8.8
CVE-2026-32624 MEDIUM
xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation
CVSS 6.5
CVE-2026-32623 HIGH
xrdp: Heap buffer overflow in NeutrinoRDP channel reassembly
CVSS 8.1
Details
Vulnerabilities 2,135
Exploit Likelihood High