CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,545 vulnerabilities with CWE-122
CVE-2026-51218 HIGH
snap7 1.4.3 - Denial of Service via TS7Worker::PerformFunctionWrite()
CVSS 7.5
CVE-2026-13590 MEDIUM
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
CVSS 5.6
CVE-2026-13589 MEDIUM
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
CVSS 5.6
CVE-2026-13588 MEDIUM
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
CVSS 5.6
CVE-2026-12912 HIGH
Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image
CVSS 7.3
CVE-2026-13587 LOW
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
CVSS 3.7
CVE-2026-13574 LOW
llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
CVSS 3.3
CVE-2026-30040 MEDIUM
FastStone Image Viewer 8.3 - Heap-based Buffer Overflow via Crafted JP2 File
CVSS 6.5
CVE-2026-56789 MEDIUM
RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch Satellite Count
CVSS 6.5
CVE-2026-56123 HIGH
socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser
CVSS 8.1
CVE-2026-12844 HIGH
List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function
CVSS 7.5
CVE-2026-46752 CRITICAL
Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()
CVE-2026-12244 HIGH
NLnet Labs - Heap Overflow and Crash with Crafted SVCB RR
CVSS 8.8
CVE-2026-2050 HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-12725 MEDIUM
Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
CVSS 5.9
CVE-2026-12805 MEDIUM
OFFIS DCMTK ofxml.cc parseFile heap-based overflow
CVSS 6.3
CVE-2026-56208 HIGH
Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
CVSS 7.6
CVE-2026-3195 HIGH
QEMU virtio-snd - Heap Buffer Overflow
CVSS 7.4
CVE-2026-45696 MEDIUM
OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)
CVSS 6.5
CVE-2026-2467 HIGH
RTI Connext Professional Core Libraries - Heap-Based Buffer Overflow
CVSS 8.1
CVE-2026-42055 HIGH
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVSS 8.1
CVE-2026-12466 HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-12447 HIGH
Google Chrome - Heap-based Buffer Overflow
CVSS 8.8
CVE-2026-47747 HIGH
stable-diffusion.cpp has a Heap-based Buffer Overflow
CVSS 7.8
CVE-2026-0149 HIGH
Google Android - Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 2,545
Exploit Likelihood High