CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-20837 HIGH
Microsoft Windows Media - Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-20820 HIGH
Windows Common Log File System Driver - Buffer Overflow
CVSS 7.8
CVE-2026-20809 HIGH
Windows Kernel Memory - Privilege Escalation
CVSS 7.8
CVE-2026-0822 MEDIUM
Quickjs < 0.11.0 - Out-of-Bounds Write
CVSS 6.3
CVE-2026-0821 HIGH
Quickjs < 0.11.0 - Memory Corruption
CVSS 7.3
CVE-2026-22697 HIGH
Nasa Cryptolib < 1.4.3 - Heap Buffer Overflow
CVSS 7.5
CVE-2026-22027 MEDIUM
Nasa Cryptolib < 1.4.3 - Heap Buffer Overflow
CVSS 6.0
CVE-2026-21682 HIGH
Color Iccdev < 2.3.1.2 - Heap Buffer Overflow
CVSS 8.8
CVE-2026-21678 HIGH
Color Iccdev < 2.3.1.2 - Out-of-Bounds Write
CVSS 7.8
CVE-2026-21504 MEDIUM
Color Iccdev < 2.3.1.2 - Out-of-Bounds Write
CVSS 6.6
CVE-2026-21494 MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2026-21491 MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2026-21490 MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2026-21488 MEDIUM
Color Iccdev < 2.3.1.2 - Heap Buffer Overflow
CVSS 6.1
CVE-2026-21676 HIGH
Color Iccdev < 2.3.1.1 - Heap Buffer Overflow
CVSS 8.8
CVE-2026-21486 HIGH
Color Iccdev < 2.3.1.2 - Integer Overflow
CVSS 7.8
CVE-2025-10685 HIGH
HTTP POST with specific higher content length leads into heap corruption
CVE-2025-61154 MEDIUM
LibreDWG v0.13.3.7571-0.13.3.7835 - DoS
CVSS 6.5
CVE-2025-69247 HIGH
free5GC go-upf <1.2.8 - Buffer Overflow
CVSS 7.5
CVE-2025-14905 HIGH
389-ds-base - Memory Corruption
CVSS 7.2
CVE-2025-70122 HIGH
free5GC v4.0.1 - Buffer Overflow
CVSS 7.5
CVE-2025-67433 HIGH
Open TFTP Server MultiThreaded <1.7 - DoS
CVSS 7.5
CVE-2025-57709 HIGH
Qnap Qsync Central < 5.0.0.4 - Out-of-Bounds Write
CVSS 8.1
CVE-2025-52870 HIGH
Qnap Qsync Central < 5.0.0.4 - Heap Buffer Overflow
CVSS 8.1
CVE-2025-52869 HIGH
Qnap Qsync Central < 5.0.0.4 - Heap Buffer Overflow
CVSS 8.1
Details
Vulnerabilities 2,135
Exploit Likelihood High