CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,312 vulnerabilities with CWE-122
CVE-2026-21239 HIGH
Windows Kernel < - Privilege Escalation
CVSS 7.8
CVE-2026-21236 HIGH
Windows Ancillary Function Driver - Buffer Overflow
CVSS 7.8
CVE-2026-23719 HIGH
Simcenter Femap, Nastran <V2512 - Buffer Overflow
CVSS 7.8
CVE-2026-24682 HIGH
FreeRDP < 3.22.0 - Heap-based Buffer Overflow in audin_server_recv_formats
CVSS 7.5
CVE-2026-24679 CRITICAL
FreeRDP < 3.22.0 - Heap-based Buffer Overflow in URBDRC Client Interface Handling
CVSS 9.1
CVE-2026-25749 MEDIUM
Vim < 9.1.2132 - Heap-based Buffer Overflow in Tag File Resolution
CVSS 6.6
CVE-2026-24925 HIGH
HarmonyOS - Heap-based Buffer Overflow in Image Module
CVSS 7.3
CVE-2026-24922 MEDIUM
HarmonyOS - Heap-based Buffer Overflow in HDC Module
CVSS 6.9
CVE-2026-25583 HIGH
iccDEV < 2.3.1.3 - Heap Buffer Overflow via Malformed ICC Profile File
CVSS 7.8
CVE-2026-25582 HIGH
iccdev < 2.3.1.3 - Heap Buffer Overflow Read in CIccIO::WriteUInt16Float()
CVSS 7.8
CVE-2026-1861 HIGH
Google Chrome <144.0.7559.132 - Buffer Overflow
CVSS 8.8
CVE-2026-20408 HIGH
MediaTek Software Development Kit < 7.6.7.2 - Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-23567 MEDIUM
TeamViewer DEX Client <26.1 - Buffer Overflow
CVSS 6.5
CVE-2026-24857 CRITICAL
bulk_extractor >= 1.4 - Heap-Based Buffer Overflow in RAR PPM LZ Decoding
CVSS 9.8
CVE-2026-24852 MEDIUM
iccDEV < 2.3.1.2 - Heap Buffer Over-Read via Non-Null-Terminated Buffer
CVSS 6.1
CVE-2026-24829 MEDIUM
Is-Daouda is-Engine <3.3.4 - Heap-based Buffer Overflow
CVSS 6.5
CVE-2026-24822 CRITICAL
wxhelper <3.9.10.19-v1 - Heap-based Buffer Overflow
CVE-2026-1283 HIGH
SOLIDWORKS eDrawings <2026 - Buffer Overflow
CVSS 7.8
CVE-2026-24412 HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagXmlSegmentedCurve::ToXml()
CVSS 8.8
CVE-2026-24406 HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagNamedColor2::SetSize()
CVSS 8.8
CVE-2026-24405 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccMpeCalculator::Read()
CVSS 8.8
CVE-2026-0793 CRITICAL
ALGO 8180 IP Audio Alerter Firmware - Unauthenticated Heap-based Buffer Overflow via InformaCast
CVSS 9.8
CVE-2026-23876 HIGH
ImageMagick <7.1.2-13 & <6.9.13-38 - Buffer Overflow
CVSS 8.1
CVE-2026-23732 HIGH
FreeRDP < 3.21.0 - Heap-based Buffer Overflow via FastGlyph Parsing
CVSS 7.5
CVE-2026-23534 CRITICAL
FreeRDP < 3.21.0 - Heap-based Buffer Overflow in ClearCodec Bands Decode Path
CVSS 9.8
Details
Vulnerabilities 2,312
Exploit Likelihood High