CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-26156 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-27286 MEDIUM
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 5.5
CVE-2026-27285 MEDIUM
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 5.5
CVE-2026-27238 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-22828 HIGH
Fortinet FortiAnalyzer Cloud < 7.6.4 - Buffer Overflow
CVSS 8.1
CVE-2026-40310 MEDIUM
ImageMagick: Heap out-of-bounds write in JP2 encoder
CVSS 5.5
CVE-2026-40183 MEDIUM
ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float
CVSS 5.5
CVE-2026-40169 MEDIUM
ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders
CVSS 6.2
CVE-2026-33901 HIGH
ImageMagick has a Heap Buffer Overflow via MVG decoder
CVSS 7.5
CVE-2026-33899 MEDIUM
ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML
CVSS 5.3
CVE-2026-32316 HIGH
jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow
CVSS 8.2
CVE-2026-30999 HIGH
FFmpeg 8.0.1 - Buffer Overflow
CVSS 7.5
CVE-2026-34865 CRITICAL
Huawei HarmonyOS < 6.0.0 - Out-of-Bounds Access
CVSS 9.1
CVE-2026-25205 HIGH
Samsung Open Source Escargot - Buffer Overflow
CVSS 7.4
CVE-2026-4153 HIGH
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-4152 HIGH
GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-29043 MEDIUM
HDF5 H5T__ref_mem_setnull Heap Buffer Overflow
CVSS 5.5
CVE-2026-5448 MEDIUM
1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore
CVSS 4.3
CVE-2026-5264 CRITICAL
DTLS 1.3 ACK heap buffer overflow
CVSS 9.8
CVE-2026-5447 HIGH
Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier
CVSS 7.5
CVE-2026-5187 CRITICAL
Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL
CVSS 9.8
CVE-2026-5869 MEDIUM
Google Chrome < 147.0.7727.55 - Buffer Overflow
CVSS 4.3
CVE-2026-5868 HIGH
Google Chrome < 147.0.7727.55 - Buffer Overflow
CVSS 8.8
CVE-2026-5867 MEDIUM
Google Chrome < 147.0.7727.55 - Buffer Overflow
CVSS 4.3
CVE-2026-5864 MEDIUM
Google Chrome < 147.0.7727.55 - Buffer Overflow
CVSS 4.3
Details
Vulnerabilities 2,135
Exploit Likelihood High