CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,312 vulnerabilities with CWE-122
CVE-2026-30931 MEDIUM
ImageMagick <7.1.2-16 - Buffer Overflow
CVSS 6.8
CVE-2026-28686 MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Buffer Overflow
CVSS 6.8
CVE-2026-3713 MEDIUM
libpng <= 1.6.55 - Heap-Based Buffer Overflow in pnm2png
CVSS 5.3
CVE-2026-28546 MEDIUM
HarmonyOS - Heap-based Buffer Overflow in Scanning Module
CVSS 5.9
CVE-2026-3544 HIGH
Google Chrome <145.0.7632.159 - Buffer Overflow
CVSS 8.8
CVE-2026-20053 MEDIUM
Cisco Snort 3 - Unauthenticated Denial of Service via VBA Data Decompression
CVSS 5.8
CVE-2026-29022 HIGH
dr_libs <=0.14.4 - Memory Corruption
CVSS 7.3
CVE-2026-22891 CRITICAL
libbiosig 3.9.2 and Master Branch - Heap-based Buffer Overflow in Intan CLP Parsing
CVSS 9.8
CVE-2026-20777 HIGH
The Biosig Project libbiosig 3.9.2 - Buffer Overflow
CVSS 8.1
CVE-2026-3463 LOW
xlnt-community xlnt <=1.6.1 - Buffer Overflow
CVSS 3.3
CVE-2026-0006 CRITICAL
Google Android - Heap Buffer Overflow
CVSS 9.8
CVE-2026-3407 LOW
YosysHQ yosys <=0.62 - Buffer Overflow
CVSS 3.3
CVE-2026-3393 LOW
jarikomppa soloud <20200207 - Buffer Overflow
CVSS 3.3
CVE-2026-28421 MEDIUM
Vim < 9.2.0077 - Heap Buffer Overflow and Denial of Service via Swap File Recovery
CVSS 5.3
CVE-2026-28420 MEDIUM
Vim < 9.2.0076 - Heap-based Buffer Overflow in Terminal Emulator
CVSS 4.4
CVE-2026-28418 MEDIUM
Vim < 9.2.0074 - Heap-based Buffer Overflow in Emacs-style Tags File Parser
CVSS 4.4
CVE-2026-3281 MEDIUM
libvips 8.19.0 - Heap-Based Buffer Overflow in vips_bandrank_build
CVSS 5.3
CVE-2026-2597 HIGH
Crypt::SysRandom::XS <0.010 - Buffer Overflow
CVSS 7.5
CVE-2026-23750 HIGH
Golioth Pouch 0.1.0 - Buffer Overflow
CVSS 8.1
CVE-2026-27799 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 4.0
CVE-2026-3147 MEDIUM
libvips < 8.18.0 - Heap-Based Buffer Overflow in CSV Load Function
CVSS 5.3
CVE-2026-26284 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25897 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25794 HIGH
ImageMagick <7.1.2-15 - Memory Corruption
CVSS 8.2
CVE-2026-25576 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 5.1
Details
Vulnerabilities 2,312
Exploit Likelihood High