CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,312 vulnerabilities with CWE-122
CVE-2026-7353
HIGH
Google Chrome < 147.0.7727.138 - Heap-based Buffer Overflow in Skia
CVSS 8.3
CVE-2026-7339
HIGH
Google Chrome < 147.0.7727.138 - Heap-based Buffer Overflow in WebRTC
CVSS 8.8
CVE-2026-20766
HIGH
Milesight Cameras Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-7040
HIGH
Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters
CVSS 7.5
CVE-2026-33602
MEDIUM
Off-by-one access when processing crafted UDP responses
CVSS 6.5
CVE-2026-6846
HIGH
Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVSS 7.8
CVE-2026-40706
HIGH
NTFS-3G 2022.10.3-2026.2.25 - Heap-based Buffer Overflow in ntfs_build_permissions_posix()
CVSS 8.4
CVE-2026-40614
HIGH
PJSIP: Heap buffer overflow in Opus codec decoding
CVSS 8.8
CVE-2026-5450
CRITICAL
glibc 2.7-2.43 - Heap-based Buffer Overflow via scanf %mc with Explicit Width
CVSS 9.8
CVE-2026-32135
HIGH
NanoMQ has Heap Buffer Overflow in URI Parameter Parsing
CVSS 7.5
CVE-2026-41445
HIGH
KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()
CVSS 8.8
CVE-2026-32961
MEDIUM
silex technology SD-330AC and AMC Manager - Heap-based Buffer Overflow in Packet Data Processing
CVSS 5.3
CVE-2026-32956
CRITICAL
SD-330AC and AMC Manager - Heap-based Buffer Overflow in Redirect URL Processing
CVSS 9.8
CVE-2026-35512
HIGH
xrdp: Heap buffer overflow in EGFX channel
CVSS 8.8
CVE-2026-32624
MEDIUM
xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation
CVSS 6.5
CVE-2026-32623
HIGH
xrdp: Heap buffer overflow in NeutrinoRDP channel reassembly
CVSS 8.1
CVE-2026-6491
MEDIUM
libvips nip2 vips7compat.c im_minpos_vec heap-based overflow
CVSS 5.3
CVE-2026-40504
CRITICAL
Creolabs Gravity < 0.9.6 Heap Buffer Overflow via gravity_vm_exec
CVSS 9.8
CVE-2026-6361
HIGH
Google Chrome < 147.0.7727.101 - Heap-based Buffer Overflow in PDFium via Crafted PDF File
CVSS 8.3
CVE-2026-6306
HIGH
Google Chrome < 147.0.7727.101 - Remote Code Execution via PDFium Heap Buffer Overflow
CVSS 8.8
CVE-2026-6305
HIGH
Google Chrome < 147.0.7727.101 - Remote Code Execution via PDFium Heap Buffer Overflow
CVSS 8.8
CVE-2026-6298
MEDIUM
Google Chrome < 147.0.7727.101 - Heap-based Buffer Overflow in Skia
CVSS 4.3
CVE-2026-6296
CRITICAL
Google Chrome < 147.0.7727.101 - Heap-based Buffer Overflow in ANGLE via Crafted HTML Page
CVSS 9.6
CVE-2026-27301
MEDIUM
Adobe Framemaker | Heap-based Buffer Overflow (CWE-122)
CVSS 5.5
CVE-2026-27293
HIGH
Adobe Framemaker | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
Details
Vulnerabilities
2,312
Exploit Likelihood
High