CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,135 vulnerabilities with CWE-122
CVE-2026-28842
HIGH
Apple Macos < 26.4 - Buffer Overflow
CVSS 7.5
CVE-2026-27654
HIGH
NGINX ngx_http_dav_module vulnerability
CVSS 8.2
CVE-2026-4675
HIGH
Google Chrome < 146.0.7680.165 - Buffer Overflow
CVSS 8.8
CVE-2026-4673
HIGH
Google Chrome < 146.0.7680.165 - Buffer Overflow
CVSS 8.8
CVE-2026-33298
HIGH
llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing
CVSS 7.8
CVE-2026-33164
HIGH
NULL Pointer Dereference in libde265
CVSS 7.5
CVE-2026-32710
HIGH
Heap-based Buffer Overflow in MariaDB
CVSS 8.5
CVE-2026-32945
HIGH
PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser
CVE-2026-4463
HIGH
Google Chrome < 146.0.7680.153 - Buffer Overflow
CVSS 8.8
CVE-2026-4455
HIGH
Google Chrome < 146.0.7680.153 - Buffer Overflow
CVSS 8.8
CVE-2026-4448
HIGH
Google Chrome < 146.0.7680.153 - Buffer Overflow
CVSS 8.8
CVE-2026-4443
HIGH
Google Chrome < 146.0.7680.153 - Buffer Overflow
CVSS 8.8
CVE-2026-4442
HIGH
Google Chrome < 146.0.7680.153 - Buffer Overflow
CVSS 8.8
CVE-2026-4395
CRITICAL
Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path
CVSS 9.8
CVE-2026-3549
CRITICAL
wolfSSL < 5.9.0 - Heap Buffer Overflow in TLS 1.3 ECH Parsing
CVSS 9.8
CVE-2026-3229
MEDIUM
Integer Overflow in Certificate Chain Allocation
CVSS 5.5
CVE-2026-3548
CRITICAL
Buffer overflow in CRL number parsing in wolfSSL
CVSS 9.8
CVE-2026-2646
HIGH
Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
CVSS 8.1
CVE-2026-31971
HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
CVE-2026-31970
HIGH
HTSlib BGZF index file reader has a heap buffer overflow
CVSS 8.1
CVE-2026-31969
HIGH
HTSlib CRAM decoder has a heap buffer overflow
CVSS 8.1
CVE-2026-31968
HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
CVE-2026-31963
HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.1
CVE-2026-31962
HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.8
CVE-2026-4177
CRITICAL
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
CVSS 9.1
Details
Vulnerabilities
2,135
Exploit Likelihood
High