CWE-122: Heap-based Buffer Overflow — known CVE vulnerabilities
CVEs classified under CWE-122 (Heap-based Buffer Overflow), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-10747 — CVSS 10.0 (critical): IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer…
CVE-2026-46752: Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0…
CVE-2026-24822: Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with…
CVE-2025-23123 — CVSS 10.0 (critical): A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow…
CVE-2022-34819 — CVSS 10.0 (critical): A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC…
CVE-2026-10858 — CVSS 9.9 (critical): IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute…
CVE-2026-44050 — CVSS 9.9 (critical): A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker…
CVE-2016-15059 — CVSS 9.8 (critical): Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in…
CVE-2026-58264 — CVSS 9.8 (critical): FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler…
CVE-2026-54627 — CVSS 9.8 (critical): SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and…
CVE-2026-54626 — CVSS 9.8 (critical): SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and…
CVE-2026-91106 — CVSS 9.8 (critical): HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components…
CVE-2026-91105 — CVSS 9.8 (critical): HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components…
CVE-2026-91104 — CVSS 9.8 (critical): HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components…
CVE-2026-91098 — CVSS 9.8 (critical): HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components…
CVE-2026-82717 — CVSS 9.8 (critical): In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain…
CVE-2026-81642 — CVSS 9.8 (critical): In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and…
CVE-2026-39919 — CVSS 9.8 (critical): Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that…
CVE-2026-85103 — CVSS 9.8 (critical): A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on…
CVE-2026-21096 — CVSS 9.8 (critical): Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute…
CVE-2026-21095 — CVSS 9.8 (critical): Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute…
CVE-2026-49921 — CVSS 9.8 (critical): In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with…
CVE-2026-78509 — CVSS 9.8 (critical): Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-69829 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
CVE-2026-69824 — CVSS 9.8 (critical): Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
CVE-2026-69769 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
CVE-2026-69768 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
CVE-2026-69590 — CVSS 9.8 (critical): Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-69586 — CVSS 9.8 (critical): Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
CVE-2026-69496 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
CVE-2026-69493 — CVSS 9.8 (critical): Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
CVE-2026-69491 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
CVE-2026-69463 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
CVE-2026-69431 — CVSS 9.8 (critical): Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
CVE-2026-69408 — CVSS 9.8 (critical): Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CVE-2026-69276 — CVSS 9.8 (critical): Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a…
CVE-2025-70293 — CVSS 9.8 (critical): An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size…
CVE-2026-63633 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls…
CVE-2026-55194 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_cl…
CVE-2026-55191 — CVSS 9.8 (critical): FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an…
CVE-2026-75143 — CVSS 9.8 (critical): FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored…
CVE-2026-58081 — CVSS 9.8 (critical): Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before…
CVE-2026-67868 — CVSS 9.8 (critical): A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems…
CVE-2026-65791 — CVSS 9.8 (critical): Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-67873 — CVSS 9.8 (critical): A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because…
CVE-2017-20241 — CVSS 9.8 (critical): Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially…