CWE-122: Heap-based Buffer Overflow — known CVE vulnerabilities
CVEs classified under CWE-122 (Heap-based Buffer Overflow), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-46752: Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0…
CVE-2026-24822: Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with…
CVE-2025-23123 — CVSS 10.0 (critical): A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow…
CVE-2022-34819 — CVSS 10.0 (critical): A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC…
CVE-2026-44050 — CVSS 9.9 (critical): A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker…
CVE-2026-75143 — CVSS 9.8 (critical): FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored…
CVE-2026-67868 — CVSS 9.8 (critical): A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems…
CVE-2026-65791 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-67873 — CVSS 9.8 (critical): A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because…
CVE-2017-20241 — CVSS 9.8 (critical): Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially…
CVE-2026-67191 — CVSS 9.8 (critical): Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated…
CVE-2026-55971 — CVSS 9.8 (critical): Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are…
CVE-2026-56165 — CVSS 9.8 (critical): Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-41252 — CVSS 9.8 (critical): xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer…
CVE-2026-64620 — CVSS 9.8 (critical): FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The…
CVE-2026-56159 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-55010 — CVSS 9.8 (critical): Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50518 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50447 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-54990 — CVSS 9.8 (critical): Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-49172 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
CVE-2026-42990 — CVSS 9.8 (critical): Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
CVE-2026-57156 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer…
CVE-2026-49841 — CVSS 9.8 (critical): FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software…
CVE-2026-47291 — CVSS 9.8 (critical): Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
CVE-2026-8175 — CVSS 9.8 (critical): IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix…
CVE-2026-0264 — CVSS 9.8 (critical): A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated…
CVE-2026-41096 — CVSS 9.8 (critical): Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-28780 — CVSS 9.8 (critical): Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this…
CVE-2025-70067 — CVSS 9.8 (critical): Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryPr…
CVE-2026-32956 — CVSS 9.8 (critical): SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect…
CVE-2026-40504 — CVSS 9.8 (critical): Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write…
CVE-2026-5264 — CVSS 9.8 (critical): Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap…
CVE-2026-5187 — CVSS 9.8 (critical): Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates…
CVE-2026-32945 — CVSS 9.8 (critical): PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer…
CVE-2026-4395 — CVSS 9.8 (critical): Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write…
CVE-2026-3549 — CVSS 9.8 (critical): Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which…
CVE-2006-10003 — CVSS 9.8 (critical): XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize -…
CVE-2026-31806 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes…
CVE-2026-22891 — CVSS 9.8 (critical): A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master…
CVE-2026-0006 — CVSS 9.8 (critical): In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code…
CVE-2019-25327 — CVSS 9.8 (critical): Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute…
CVE-2026-26011 — CVSS 9.8 (critical): navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in…
CVE-2020-37162 — CVSS 9.8 (critical): Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute…
CVE-2026-23534 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the…
CVE-2026-23533 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the…
CVE-2026-23532 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the…
CVE-2026-23531 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present…
CVE-2026-23530 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not…