CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,887 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4323 — Fluent Bit Memory Corruption Vulnerability
- CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerability
- CVE-2026-78948 — Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code out
- CVE-2026-87654 — Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbi
- CVE-2026-87527 — Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code out
- CVE-2026-79130 — Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code out
- CVE-2026-17758 — Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a
- CVE-2026-17680 — Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had comp
- CVE-2026-13798 — Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised
- CVE-2026-24822 — a heap-based buffer overflow vulnerability in ttttupup/wxhelper via src/mongoose.
- CVE-2025-2618 — D-Link DAP-1620 Path api set_ws_action heap-based overflow
- CVE-2025-11778 — Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50
- CVE-2026-87579 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in
- CVE-2026-87430 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbit
- CVE-2026-79231 — Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code ins
- CVE-2026-79142 — Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbi
- CVE-2026-78891 — Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code in
- CVE-2026-17951 — Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bo
- CVE-2026-17935 — Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co
- CVE-2026-14385 — Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of
Recently published
- CVE-2026-85103 — Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
- CVE-2026-87430 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbit
- CVE-2026-87579 — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in
- CVE-2026-87654 — Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbi
- CVE-2026-87527 — Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code out
- CVE-2026-53938 — OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)
- CVE-2026-81993 — Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
- CVE-2026-81992 — Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
- CVE-2026-82006 — Photoshop Desktop | Heap-based Buffer Overflow (CWE-122)
- CVE-2026-86716 — Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
- CVE-2026-20502 — In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p
- CVE-2026-20501 — In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of p
- CVE-2026-86142 — In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer l
- CVE-2026-57164 — PJSIP: Heap overflow in the HTTP client
- CVE-2026-18341 — IBM i is Affected By Buffer Overflow Vulnerability []
- CVE-2026-81665 — Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
- CVE-2026-83959 — Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
- CVE-2026-53720 — pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
- CVE-2026-78689 — NGINX ngx_http_js_module vulnerablility
- CVE-2026-84269 — Gvfs: afp: heap-based buffer overflow in dsi read path