CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2026-25646 HIGH
Libpng < 1.6.55 - Buffer Over-read
CVSS 8.1
CVE-2026-21358 MEDIUM
Adobe Indesign < 20.5.2 - Out-of-Bounds Write
CVSS 5.5
CVE-2026-21357 HIGH
Adobe Indesign < 20.5.2 - Out-of-Bounds Write
CVSS 7.8
CVE-2026-21259 HIGH
Microsoft Office Excel - Privilege Escalation
CVSS 7.8
CVE-2026-21248 HIGH
Windows Hyper-V - Buffer Overflow
CVSS 7.3
CVE-2026-21247 HIGH
Windows Hyper-V - Code Injection
CVSS 7.3
CVE-2026-21246 HIGH
Microsoft Graphics Component - Privilege Escalation
CVSS 7.8
CVE-2026-21245 HIGH
Microsoft Windows Kernel Heap-based Buffer Overflow - Privilege Escalation
CVSS 7.8
CVE-2026-21244 HIGH
Windows Hyper-V - Buffer Overflow
CVSS 7.3
CVE-2026-21239 HIGH
Windows Kernel < - Privilege Escalation
CVSS 7.8
CVE-2026-21236 HIGH
Windows Ancillary Function Driver - Buffer Overflow
CVSS 7.8
CVE-2026-23719 HIGH
Simcenter Femap, Nastran <V2512 - Buffer Overflow
CVSS 7.8
CVE-2026-24682 HIGH
Freerdp < 3.22.0 - Heap Buffer Overflow
CVSS 7.5
CVE-2026-24679 CRITICAL
Freerdp < 3.22.0 - Heap Buffer Overflow
CVSS 9.1
CVE-2026-25749 MEDIUM
Vim <9.1.2132 - Buffer Overflow
CVSS 6.6
CVE-2026-24925 HIGH
Huawei Harmonyos - Out-of-Bounds Write
CVSS 7.3
CVE-2026-24922 MEDIUM
Huawei Harmonyos - Heap Buffer Overflow
CVSS 6.9
CVE-2026-25583 HIGH
iccDEV <2.3.1.3 - Buffer Overflow
CVSS 7.8
CVE-2026-25582 HIGH
iccDEV <2.3.1.3 - Buffer Overflow
CVSS 7.8
CVE-2026-1861 HIGH
Google Chrome <144.0.7559.132 - Buffer Overflow
CVSS 8.8
CVE-2026-20408 HIGH
Wlan - Buffer Overflow
CVSS 8.8
CVE-2026-23567 MEDIUM
TeamViewer DEX Client <26.1 - Buffer Overflow
CVSS 6.5
CVE-2026-24857 CRITICAL
Simsong Bulk Extractor - Out-of-Bounds Write
CVSS 9.8
CVE-2026-24852 MEDIUM
Color Iccdev < 2.3.1.2 - Heap Buffer Overflow
CVSS 6.1
CVE-2026-24829 MEDIUM
Is-Daouda is-Engine <3.3.4 - Heap-based Buffer Overflow
CVSS 6.5
Details
Vulnerabilities 2,135
Exploit Likelihood High