Vulnerabilities (CVE)

Filtered by CWE-122
Total 3151 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-81354 1 Microsoft 8 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 5 more 2026-09-10 N/A 8.2 HIGH
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
CVE-2026-80087 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-09-10 N/A 6.5 MEDIUM
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-69778 1 Microsoft 6 365 Apps, Access, Office 2016 and 3 more 2026-09-10 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-77907 1 Microsoft 1 Visual Studio 2026 2026-09-10 N/A 8.8 HIGH
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69529 1 Microsoft 6 365 Apps, Access, Office 2016 and 3 more 2026-09-10 N/A 8.8 HIGH
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-69477 1 Microsoft 5 365 Apps, Access, Office 2019 and 2 more 2026-09-10 N/A 7.3 HIGH
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
CVE-2026-69481 2026-09-10 N/A 8.0 HIGH
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.
CVE-2026-68897 2026-09-10 N/A 7.0 HIGH
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-68844 2026-09-10 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CVE-2026-49882 2026-09-10 N/A 8.8 HIGH
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-81993 3 Adobe, Apple, Microsoft 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more 2026-09-10 N/A 5.5 MEDIUM
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-42945 1 F5 7 Dos, Nginx Gateway Fabric, Nginx Ingress Controller and 4 more 2026-09-10 N/A 8.1 HIGH
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-25249 2 Fortinet, Siemens 5 Fortios, Fortisase, Fortiswitchmanager and 2 more 2026-09-10 N/A 8.1 HIGH
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVE-2026-87654 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 9.6 CRITICAL
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87579 1 Google 1 Chrome 2026-09-10 N/A 8.8 HIGH
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87527 1 Google 1 Chrome 2026-09-10 N/A 9.6 CRITICAL
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-87430 1 Google 1 Chrome 2026-09-10 N/A 8.8 HIGH
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-85103 2026-09-10 N/A 9.8 CRITICAL
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
CVE-2026-69688 2026-09-10 N/A 7.1 HIGH
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-68877 2026-09-10 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.