CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-3281 MEDIUM
libvips 8.19.0 - Buffer Overflow
CVSS 5.3
CVE-2026-2597 HIGH
Crypt::SysRandom::XS <0.010 - Buffer Overflow
CVSS 7.5
CVE-2026-23750 HIGH
Golioth Pouch 0.1.0 - Buffer Overflow
CVSS 8.1
CVE-2026-27799 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 4.0
CVE-2026-3147 MEDIUM
libvips <=8.18.0 - Buffer Overflow
CVSS 5.3
CVE-2026-26284 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25897 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 6.5
CVE-2026-25794 HIGH
ImageMagick <7.1.2-15 - Memory Corruption
CVSS 8.2
CVE-2026-25576 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Buffer Overflow
CVSS 5.1
CVE-2026-2913 LOW
libvips <=8.19.0 - Buffer Overflow
CVSS 2.5
CVE-2026-27168 HIGH
SAIL XWD Parser - Buffer Overflow
CVSS 8.8
CVE-2026-2047 HIGH
GIMP - Heap-based Buffer Overflow RCE
CVSS 7.8
CVE-2026-0797 HIGH
GIMP - Heap-based Buffer Overflow RCE
CVSS 7.8
CVE-2026-26967 MEDIUM
PJSIP <=2.16 - Buffer Overflow
CVSS 5.3
CVE-2026-26200 HIGH
HDF5 <1.14.4-2 - Buffer Overflow
CVSS 7.8
CVE-2026-2650 HIGH
Google Chrome <145.0.7632.109 - Buffer Overflow
CVSS 8.8
CVE-2026-2648 HIGH
Google Chrome <145.0.7632.109 - Memory Corruption
CVSS 8.8
CVE-2026-2661 LOW
Squirrel up to 3.2 - Buffer Overflow
CVSS 3.3
CVE-2026-2653 MEDIUM
admesh <=0.98.5 - Buffer Overflow
CVSS 5.3
CVE-2026-2474 HIGH
Crypt::URandom 0.41-0.54 - Buffer Overflow
CVSS 7.5
CVE-2026-2447 HIGH
libvpx - Buffer Overflow
CVSS 8.8
CVE-2026-26011 CRITICAL
Nav2 AMCL <1.3.11 - Memory Corruption
CVSS 9.8
CVE-2026-2007 HIGH
PostgreSQL <18.1-18.0 - Buffer Overflow
CVSS 8.2
CVE-2026-2005 HIGH
PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE
CVSS 8.8
CVE-2026-2314 HIGH
Google Chrome <145.0.7632.45 - Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,135
Exploit Likelihood High