CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,312 vulnerabilities with CWE-122
CVE-2026-33020 HIGH
libsixel: Integer Overflow in write_png_to_file() leads to Heap-based Buffer Overflow
CVSS 7.1
CVE-2026-34630 HIGH
Bridge | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-27313 HIGH
Bridge | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-27312 HIGH
Bridge | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-27311 HIGH
Bridge | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-27310 HIGH
Bridge | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-34629 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-34628 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-34627 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-32223 MEDIUM
Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
CVSS 6.8
CVE-2026-32221 HIGH
Windows Graphics Component Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-32149 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.3
CVE-2026-32093 HIGH
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-32087 HIGH
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-26180 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26176 HIGH
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26156 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-27286 MEDIUM
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 5.5
CVE-2026-27285 MEDIUM
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 5.5
CVE-2026-27238 HIGH
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVSS 7.8
CVE-2026-22828 HIGH
FortiAnalyzer/FortiManager Cloud 7.6.2-7.6.4 - Unauthenticated RCE via Heap Overflow
CVSS 8.1
CVE-2026-40310 MEDIUM
ImageMagick: Heap out-of-bounds write in JP2 encoder
CVSS 5.5
CVE-2026-40183 MEDIUM
ImageMagick: Heap buffer overflow when encoding JXL image with a 16-bit float
CVSS 5.5
CVE-2026-40169 MEDIUM
ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders
CVSS 6.2
CVE-2026-33901 HIGH
ImageMagick MVG Decoder - Heap Buffer Overflow
CVSS 7.5
Details
Vulnerabilities 2,312
Exploit Likelihood High