CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,545 vulnerabilities with CWE-122
CVE-2026-0132 HIGH
Google Android - Remote Code Execution
CVSS 8.8
CVE-2026-0130 LOW
Google Android - Buffer Overflow
CVSS 3.5
CVE-2026-47964 HIGH
Adobe Dng SDK < 1.7.1 2536 - Buffer Overflow
CVSS 7.8
CVE-2026-47749 HIGH
stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files
CVSS 7.8
CVE-2026-8484 MEDIUM
Heap buffer overflow in Jansi
CVE-2026-52720 HIGH
Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb
CVSS 8.8
CVE-2026-12193 HIGH
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
CVSS 7.8
CVE-2026-48914 MEDIUM
Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling
CVSS 6.7
CVE-2026-12030 HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.3
CVE-2026-12010 HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.3
CVE-2026-53465 MEDIUM
ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
CVSS 6.2
CVE-2026-48994 MEDIUM
ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems
CVSS 5.9
CVE-2026-46692 MEDIUM
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
CVSS 4.1
CVE-2026-46520 HIGH
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVSS 7.5
CVE-2026-2049 HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-11604 MEDIUM
Openvpn Ovpn-dco-win < 2.5.8 - Heap-based Buffer Overflow
CVE-2026-11884 MEDIUM
389 Directory Server - Heap Buffer Overflow in Objectclass Serialization
CVSS 6.5
CVE-2026-45542 HIGH
ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth
CVSS 7.1
CVE-2026-48292 HIGH
Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-48291 HIGH
Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-47952 HIGH
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-11824 HIGH
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
CVSS 7.8
CVE-2026-11822 HIGH
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
CVSS 7.8
CVE-2026-34707 HIGH
InCopy | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-34701 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
Details
Vulnerabilities 2,545
Exploit Likelihood High