CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,312 vulnerabilities with CWE-122
CVE-2026-4455 HIGH
Google Chrome < 146.0.7680.153 - Heap-based Buffer Overflow in PDFium via Crafted PDF File
CVSS 8.8
CVE-2026-4448 HIGH
Google Chrome < 146.0.7680.153 - Heap-based Buffer Overflow in ANGLE via Crafted HTML Page
CVSS 8.8
CVE-2026-4443 HIGH
Google Chrome < 146.0.7680.153 - Remote Code Execution via WebAudio Heap Buffer Overflow
CVSS 8.8
CVE-2026-4442 HIGH
Google Chrome < 146.0.7680.153 - Heap-based Buffer Overflow in CSS
CVSS 8.8
CVE-2026-4395 CRITICAL
Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path
CVSS 9.8
CVE-2026-3549 CRITICAL
wolfSSL < 5.9.0 - Heap Buffer Overflow in TLS 1.3 ECH Parsing
CVSS 9.8
CVE-2026-3229 MEDIUM
Integer Overflow in Certificate Chain Allocation
CVSS 5.5
CVE-2026-3548 CRITICAL
Buffer overflow in CRL number parsing in wolfSSL
CVSS 9.8
CVE-2026-2646 HIGH
Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
CVSS 8.1
CVE-2026-31971 HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
CVE-2026-31970 HIGH
HTSlib BGZF GZI Index - Heap Buffer Overflow
CVSS 8.1
CVE-2026-31969 HIGH
HTSlib CRAM BYTE_ARRAY_STOP - Heap Buffer Overflow
CVSS 8.1
CVE-2026-31968 HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
CVE-2026-31963 HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.1
CVE-2026-31962 HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.8
CVE-2026-4177 CRITICAL
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
CVSS 9.1
CVE-2026-3561 HIGH
Philips Hue Bridge - Heap-based Buffer Overflow RCE
CVSS 8.0
CVE-2026-3560 HIGH
Philips Hue Bridge - Buffer Overflow RCE
CVSS 8.8
CVE-2026-3557 HIGH
Philips Hue Bridge - Heap-based Buffer Overflow RCE
CVSS 8.0
CVE-2026-3556 HIGH
Philips Hue Bridge - Buffer Overflow RCE
CVSS 8.8
CVE-2026-3555 HIGH
Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-3085 HIGH
GStreamer - Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-3082 HIGH
GStreamer - Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-2920 HIGH
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-28519 HIGH
arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 2,312
Exploit Likelihood High