CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,559 vulnerabilities with CWE-122
CVE-2026-54990 CRITICAL
Microsoft Windows 11 Version 24H2 - Remote Desktop Client Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-54987 HIGH
Microsoft Windows 10 Version 1607 - Windows Overlay Filter Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-54986 HIGH
Microsoft Windows 10 Version 1607 - Windows Win32k Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-54132 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Kernel Elevation of Privilege Vulnerability
CVSS 6.8
CVE-2026-54122 HIGH
Microsoft Windows 10 Version 1607 < 10.0.14393.9339 - Buffer Overflow
CVSS 8.4
CVE-2026-54109 HIGH
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50696 HIGH
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVSS 7.5
CVE-2026-50678 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVSS 6.6
CVE-2026-50675 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50308 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50299 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Storage Spaces Direct Remote Code Execution Vulnerability
CVSS 6.8
CVE-2026-49804 MEDIUM
Microsoft Windows 10 Version 1607 - Windows USB Video Driver Elevation of Privilege Vulnerability
CVSS 6.6
CVE-2026-49800 HIGH
Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-49797 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-49796 HIGH
Microsoft Windows 10 Version 1607 < 10.0.14393.9339 - Buffer Overflow
CVSS 7.8
CVE-2026-49793 HIGH
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-49790 HIGH
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS 7.3
CVE-2026-49184 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-49178 HIGH
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-49175 HIGH
Microsoft Windows 10 Version 21H2 - Windows DNS Client Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-49172 CRITICAL
Microsoft Windows 10 Version 1607 < 10.0.14393.9339 - Buffer Overflow
CVSS 9.8
CVE-2026-49164 HIGH
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVSS 8.1
CVE-2026-48564 HIGH
Microsoft Windows 10 Version 1607 - DHCP Server Service Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-42990 CRITICAL
Microsoft Windows 10 Version 1607 - SQL Server ODBC Driver Elevation of Privilege Vulnerability
CVSS 9.8
CVE-2026-42975 HIGH
Microsoft Windows 10 Version 1607 - Windows Bluetooth Port Driver Remote Code Execution
CVSS 8.0
Details
Vulnerabilities 2,559
Exploit Likelihood High