VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 148 of 160
  • CVE-2026-55127HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-55125HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-55123HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-55120HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-55056HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-55053HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55049HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-55048HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55043HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-55041HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55039HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55037HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55033HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-55029HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55017HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-55010CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-54124HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

  • CVE-2026-54115HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50692HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50683HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.