CWE-122
CVEs classified under CWE-122, newest first.
870 CVEsRSS
CVE-2026-62823High· 8.8Windows DHCP Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62800High· 8.8Windows SMBv3 Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62799High· 7.8Windows SMB Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62790High· 8.8Windows SMBv3 Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62781High· 8.1RPC Runtime Library Remote Code Execution Vulnerability
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
CVE-2026-62771High· 7.8Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62770High· 7.8Windows Shell Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-62769Medium· 6.7Windows DNS Elevation of Privilege Vulnerability
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62752High· 7.8Windows Kerberos Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-62741High· 7.8Windows HTTP.sys Elevation of Privilege Vulnerability
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62736High· 7.8Windows DHCP Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62732High· 7.8Windows Telephony Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-63533High· 7.8Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63532High· 7.8Microsoft Office Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62885High· 7.8Windows Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62883Medium· 6.7Windows DNS Elevation of Privilege Vulnerability
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62881Medium· 6.7Windows DNS Elevation of Privilege Vulnerability
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62822High· 8.8Windows GDI+ Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-62811High· 7.8Windows HTTP.sys Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-65774High· 7.8Windows Installer Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-65679High· 8.1Windows iSCSI Target Service Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-64920High· 7.8Microsoft Access Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64915High· 7.8Microsoft Office Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64914High· 7.8Microsoft Access Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64911High· 7.8Microsoft Office Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64909High· 7.8Microsoft Office Remote Code Execution Vulnerability
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64908High· 7.8Microsoft Access Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64906High· 7.8Microsoft Access Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64903High· 7.8Microsoft Office Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64898High· 7.8Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.