CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,135 vulnerabilities with CWE-122
CVE-2026-5858
HIGH
Google Chrome < 147.0.7727.55 - Buffer Overflow
CVSS 8.8
CVE-2026-35199
MEDIUM
SymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncation
CVSS 6.1
CVE-2026-21372
HIGH
Heap-Based Buffer Overflow in Power Management IC
CVSS 7.8
CVE-2026-34979
MEDIUM
OpenPrinting CUPS: Heap overflow in `get_options()`
CVSS 5.3
CVE-2026-5474
MEDIUM
NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow
CVSS 6.3
CVE-2026-34743
MEDIUM
XZ Utils: Buffer overflow in lzma_index_append()
CVSS 5.3
CVE-2026-34120
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34119
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-34118
MEDIUM
Heap-based Buffer Overflow Vulnerability Leading to Denial-of-Service in TP-Link Tapo C520WS
CVSS 6.5
CVE-2026-5244
HIGH
Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow
CVSS 7.3
CVE-2026-34545
HIGH
OpenEXR: integer overflow lead to OOB in HTJ2K decoder
CVSS 7.3
CVE-2026-5275
HIGH
Google Chrome < 146.0.7680.178 - Buffer Overflow
CVSS 8.8
CVE-2026-5272
HIGH
Google Chrome < 146.0.7680.178 - Buffer Overflow
CVSS 8.8
CVE-2026-5236
MEDIUM
Axiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow
CVSS 5.3
CVE-2026-5235
MEDIUM
Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow
CVSS 5.3
CVE-2026-34540
MEDIUM
iccDEV: HBO in icMemDump()
CVSS 6.2
CVE-2026-34539
MEDIUM
iccDEV: HBO in CTiffImg::WriteLine()
CVSS 6.2
CVE-2026-34535
MEDIUM
iccDEV: SEGV in CIccTagArray::Cleanup()
CVSS 6.2
CVE-2026-34534
MEDIUM
iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
CVSS 6.2
CVE-2026-5201
HIGH
Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
CVSS 7.5
CVE-2026-5185
MEDIUM
Nothings stb_image Multi-frame GIF File stb_image.h stbi__gif_load_next heap-based overflow
CVSS 5.3
CVE-2026-33987
HIGH
FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write
CVSS 7.1
CVE-2026-33986
HIGH
FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
CVSS 7.5
CVE-2026-33984
HIGH
FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
CVSS 7.5
CVE-2026-26073
MEDIUM
EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue
CVSS 5.9
Details
Vulnerabilities
2,135
Exploit Likelihood
High