CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,312 vulnerabilities with CWE-122
CVE-2026-33899
MEDIUM
ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML
CVSS 5.3
CVE-2026-32316
HIGH
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
CVSS 8.2
CVE-2026-30999
HIGH
FFmpeg < 8.0.1 - Heap-based Buffer Overflow in av_bprint_finalize()
CVSS 7.5
CVE-2026-34865
CRITICAL
HarmonyOS >=6.0.0 - Heap-based Buffer Overflow in WEB Module
CVSS 9.1
CVE-2026-25205
HIGH
Samsung Open Source Escargot >=97e8115ab1110bc502b4b5e4a0c689a71520d335 - Heap-based Buffer Overflow
CVSS 7.4
CVE-2026-4153
HIGH
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-4152
HIGH
GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-29043
MEDIUM
HDF5 H5T__ref_mem_setnull Heap Buffer Overflow
CVSS 5.5
CVE-2026-5448
MEDIUM
1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore
CVSS 4.3
CVE-2026-5264
CRITICAL
DTLS 1.3 ACK heap buffer overflow
CVSS 9.8
CVE-2026-5447
HIGH
Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier
CVSS 7.5
CVE-2026-5187
CRITICAL
Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL
CVSS 9.8
CVE-2026-5869
MEDIUM
Google Chrome < 147.0.7727.55 - Heap-based Buffer Overflow in WebML
CVSS 4.3
CVE-2026-5868
HIGH
Google Chrome < 147.0.7727.55 - Heap-based Buffer Overflow in ANGLE via Crafted HTML Page
CVSS 8.8
CVE-2026-5867
MEDIUM
Google Chrome < 147.0.7727.55 - Heap-based Buffer Overflow in WebML
CVSS 4.3
CVE-2026-5864
MEDIUM
Google Chrome < 147.0.7727.55 - Heap-based Buffer Overflow in WebAudio
CVSS 4.3
CVE-2026-5858
HIGH
Google Chrome < 147.0.7727.55 - Remote Code Execution via WebML Heap Buffer Overflow
CVSS 8.8
CVE-2026-35199
MEDIUM
SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation
CVSS 6.1
CVE-2026-21372
HIGH
Heap-Based Buffer Overflow in Power Management IC
CVSS 7.8
CVE-2026-34979
MEDIUM
OpenPrinting CUPS: Heap overflow in `get_options()`
CVSS 5.3
CVE-2026-5474
MEDIUM
NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow
CVSS 6.3
CVE-2026-34743
MEDIUM
XZ Utils: Buffer overflow in lzma_index_append()
CVSS 5.3
CVE-2026-34120
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34119
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34118
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
Details
Vulnerabilities
2,312
Exploit Likelihood
High