CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,311 vulnerabilities with CWE-122
CVE-2026-45130 MEDIUM
Vim: Heap Buffer Overflow in spell file loading
CVSS 6.6
CVE-2026-41509 CRITICAL
Integer underflow in crypto_sign_open() leads to buffer overflow
CVSS 9.8
CVE-2026-8087 MEDIUM
OSGeo gdal GDapi.c GDnentries heap-based overflow
CVSS 5.3
CVE-2026-8086 MEDIUM
OSGeo gdal SWapi.c SWnentries heap-based overflow
CVSS 5.3
CVE-2026-7900 HIGH
Google Chrome < 148.0.7778.96 - Heap-based Buffer Overflow in ANGLE
CVSS 8.3
CVE-2026-20185 HIGH
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
CVSS 7.7
CVE-2026-6210 HIGH
Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
CVE-2026-28780 CRITICAL
Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
CVSS 9.8
CVE-2026-25589 HIGH
RedisBloom RESTORE invalid memory access may allow remote code execution
CVSS 8.8
CVE-2026-25588 HIGH
RedisTimeSeries RESTORE invalid memory access may allow remote code execution
CVSS 8.8
CVE-2026-25243 HIGH
redis-server RESTORE invalid memory access may allow remote code execution
CVSS 8.8
CVE-2026-39103 MEDIUM
GPAC <v391dc7f4d234988ea0bc3cc294eb725eddf8f702 - Buffer Overflow
CVSS 5.5
CVE-2026-29004 HIGH
BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
CVSS 8.1
CVE-2026-42477 HIGH
Open CASCADE Technology V8_0_0_rc5 - Info Disclosure
CVSS 7.1
CVE-2026-42483 CRITICAL
hashcat 7.1.2 - Heap-based Buffer Overflow in Kerberos Hash Parser
CVSS 9.8
CVE-2026-5405 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-5403 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 7.8
CVE-2026-42512 HIGH
Remotely triggerable out-of-bounds heap write in dhclient
CVSS 8.1
CVE-2026-35547 HIGH
Heap overflow in libnv
CVSS 8.1
CVE-2026-6530 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-6529 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-5653 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-5402 HIGH
Heap-based Buffer Overflow in Wireshark
CVSS 8.8
CVE-2026-7378 MEDIUM
Heap-based Buffer Overflow in Wireshark
CVSS 5.5
CVE-2026-7353 HIGH
Google Chrome < 147.0.7727.138 - Heap-based Buffer Overflow in Skia
CVSS 8.3
Details
Vulnerabilities 2,311
Exploit Likelihood High