CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-26108 HIGH
Microsoft Office Excel - Buffer Overflow
CVSS 7.8
CVE-2026-25188 HIGH
Windows Telephony Service - Privilege Escalation
CVSS 8.8
CVE-2026-25173 HIGH
Windows RRAS - Memory Corruption
CVSS 8.0
CVE-2026-25172 HIGH
Windows RRAS - Memory Corruption
CVSS 8.0
CVE-2026-24288 MEDIUM
Windows Mobile Broadband - Buffer Overflow
CVSS 6.8
CVE-2026-24283 HIGH
Windows File Server - Privilege Escalation
CVSS 8.8
CVE-2026-23665 HIGH
Azure Linux VM - Privilege Escalation
CVSS 7.8
CVE-2026-30937 MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Memory Corruption
CVSS 6.8
CVE-2026-30936 MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Memory Corruption
CVSS 5.5
CVE-2026-30931 MEDIUM
ImageMagick <7.1.2-16 - Buffer Overflow
CVSS 6.8
CVE-2026-28686 MEDIUM
ImageMagick <7.1.2-16/6.9.13-41 - Buffer Overflow
CVSS 6.8
CVE-2026-3713 MEDIUM
libpng <=1.6.55 - Buffer Overflow
CVSS 5.3
CVE-2026-28546 MEDIUM
Scanning Module - Buffer Overflow
CVSS 5.9
CVE-2026-3544 HIGH
Google Chrome <145.0.7632.159 - Buffer Overflow
CVSS 8.8
CVE-2026-20053 MEDIUM
Cisco Snort 3 - Memory Corruption
CVSS 5.8
CVE-2026-29022 HIGH
dr_libs <=0.14.4 - Memory Corruption
CVSS 7.3
CVE-2026-22891 CRITICAL
libbiosig 3.9.2 - Buffer Overflow
CVSS 9.8
CVE-2026-20777 HIGH
The Biosig Project libbiosig 3.9.2 - Buffer Overflow
CVSS 8.1
CVE-2026-3463 LOW
xlnt-community xlnt <=1.6.1 - Buffer Overflow
CVSS 3.3
CVE-2026-0006 CRITICAL
Google Android - Heap Buffer Overflow
CVSS 9.8
CVE-2026-3407 LOW
YosysHQ yosys <=0.62 - Buffer Overflow
CVSS 3.3
CVE-2026-3393 LOW
jarikomppa soloud <20200207 - Buffer Overflow
CVSS 3.3
CVE-2026-28421 MEDIUM
Vim <9.2.0077 - Memory Corruption
CVSS 5.3
CVE-2026-28420 MEDIUM
Vim <9.2.0076 - Buffer Overflow
CVSS 4.4
CVE-2026-28418 MEDIUM
Vim <9.2.0074 - Buffer Overflow
CVSS 4.4
Details
Vulnerabilities 2,135
Exploit Likelihood High