CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 58 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69424 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69421 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69420 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69389 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69368 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69359 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69352 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69348 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69323 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69307 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69293 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69284 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69283 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69270 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68892 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68890 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68888 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68885 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68877 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. | ||
| CVE-2026-68850 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. |
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.