CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,311 vulnerabilities with CWE-122
CVE-2026-9939
HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-9926
HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.3
CVE-2026-9924
HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.3
CVE-2026-9915
HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.3
CVE-2026-48065
MEDIUM
pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targets
CVSS 6.7
CVE-2026-4391
MEDIUM
TeamSpeak 3 Server ECC Key heap-based overflow
CVSS 5.3
CVE-2026-8175
CRITICAL
IBM Aspera High-Speed Transfer Endpoint - Multiple Vulnerabilities in Aspera applications.
CVSS 9.8
CVE-2026-38427
HIGH
Tasmota through 15.3.0.3 - Heap Buffer Overflow in fetch_jpg()
CVSS 7.3
CVE-2026-9605
HIGH
GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
CVSS 7.3
CVE-2026-44983
HIGH
smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow
CVSS 7.3
CVE-2026-48689
CRITICAL
Pavel-odintsov Fastnetmon < 1.2.9 - Out-of-bounds Write
CVSS 9.8
CVE-2026-8834
HIGH
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 8.0
CVE-2026-48691
CRITICAL
FastNetMon Community Edition <= 1.2.9 - Heap Buffer Overflow in BGP AS_PATH Attribute Encoder
CVSS 9.8
CVE-2026-48690
HIGH
FastNetMon Community Edition <= 1.2.9 - Integer Overflow in Packet Capture Buffer Allocation
CVSS 7.1
CVE-2026-40033
HIGH
FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass
CVSS 8.8
CVE-2026-9541
MEDIUM
Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow
CVSS 5.3
CVE-2026-7310
MEDIUM
Hitachi Energy Mach HiDraw < 9.22 - Heap-based Buffer Overflow
CVE-2026-48135
MEDIUM
HTTP service can incorrectly process malformed HTTP requests
CVSS 5.3
CVE-2026-48131
HIGH
VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero
CVSS 8.1
CVE-2026-25713
HIGH
Mediaarea MediaInfoLib - Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-9502
MEDIUM
GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow
CVSS 5.3
CVE-2026-9500
MEDIUM
GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
CVSS 5.3
CVE-2026-9365
MEDIUM
Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow
CVSS 5.6
CVE-2026-9256
HIGH
F5 NGINX Plus - NGINX ngx_http_rewrite_module Vulnerability
CVSS 8.1
CVE-2026-8997
MEDIUM
Heap Buffer Overflow in vifm
Details
Vulnerabilities
2,311
Exploit Likelihood
High