CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (834)
A heap buffer overflow vulnerability in UniFi Protect Camera firmware allows remote code execution. Attackers with access to the management network ca...
May 19, 2025This critical vulnerability allows remote attackers to execute arbitrary code on systems running Weston Embedded uC-HTTP server by sending specially c...
Feb 20, 2024A heap-based buffer overflow vulnerability in Anker Eufy Homebase 2's RTSP handling allows remote code execution. Attackers can send malicious network...
Oct 12, 2021This critical vulnerability in Cisco Catalyst 9000 wireless controllers allows unauthenticated remote attackers to execute arbitrary code with adminis...
Sep 23, 2021A heap-based buffer overflow vulnerability in libbiosig's Intan CLP parsing allows arbitrary code execution when processing malicious files. This affe...
Mar 3, 2026CVE-2019-25327 is a critical buffer overflow vulnerability in Prime95 version 29.8 build 6 that allows remote attackers to execute arbitrary code by c...
Feb 12, 2026CVE-2020-37162 is a critical buffer overflow vulnerability in Wedding Slideshow Studio 1.36 that allows remote attackers to execute arbitrary code by ...
Feb 7, 2026A heap buffer overflow vulnerability in Fast DDS allows unauthenticated attackers to send a single malformed RTPS DATA_FRAG packet, causing immediate ...
Feb 3, 2026A heap buffer overflow vulnerability in bulk_extractor's embedded unrar code allows attackers to trigger out-of-bounds writes when processing crafted ...
Jan 28, 2026CVE-2026-0793 is a heap-based buffer overflow vulnerability in the InformaCast functionality of ALGO 8180 IP Audio Alerter devices, allowing remote at...
Jan 23, 2026A heap buffer overflow vulnerability in FreeRDP's ClearCodec decode path allows malicious RDP servers to trigger client-side memory corruption. This c...
Jan 19, 2026A heap buffer overflow vulnerability in FreeRDP's ClearCodec decode path allows malicious RDP servers to trigger client-side memory corruption. This a...
Jan 19, 2026A heap buffer overflow vulnerability in FreeRDP client allows malicious RDP servers to trigger client-side memory corruption. This can cause denial of...
Jan 19, 2026FreeRDP clients prior to version 3.21.0 contain a heap buffer overflow vulnerability in the planar bitmap decompression function. A malicious RDP serv...
Jan 19, 2026This CVE describes a heap buffer overflow vulnerability in FreeRDP's ClearCodec implementation. A malicious RDP server can send crafted RDPGFX surface...
Jan 19, 2026This is a critical heap buffer overflow vulnerability in FreeRDP that allows a malicious RDP server to execute arbitrary code on client systems by sen...
Jan 14, 2026This vulnerability in gpsd allows attackers to trigger heap-based out-of-bounds writes by sending specially crafted NMEA2000 PGN 129540 packets with e...
Jan 2, 2026A heap-based memory corruption vulnerability in matio library versions up to 1.5.28 allows attackers to cause out-of-bounds reads and invalid memory f...
Dec 30, 2025A heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 allows remote code execution by sending an excessively large 'meter' para...
Dec 2, 2025A stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2 allows remote attackers to execute arbitrary code through memory ...
Dec 2, 2025A heap-based buffer overflow vulnerability in Ashlar-Vellum CAD software allows attackers to read sensitive memory or execute arbitrary code by sendin...
Nov 25, 2025A heap-based buffer overflow vulnerability in MaLion and MaLionCloud's Windows Security Point component allows remote unauthenticated attackers to exe...
Nov 25, 2025A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows remote attackers to execute arbitrary code on vulnerable systems. Th...
Nov 11, 2025CVE-2025-58447 is a critical heap-based buffer overflow vulnerability in rAthena MMORPG server's login component. Remote attackers can send specially ...
Sep 9, 2025This critical vulnerability in Android's Skia graphics library allows remote attackers to execute arbitrary code with system privileges without user i...
Sep 2, 2025A heap-based buffer overflow vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to send specially crafted input ...
Aug 27, 2025A heap-based buffer overflow vulnerability in libbiosig's Nex file parser allows arbitrary code execution when processing malicious .nex files. This a...
Aug 25, 2025A heap-based buffer overflow vulnerability in libbiosig's ISHNE parsing allows arbitrary code execution when processing malicious ECG annotation files...
Aug 25, 2025A heap-based buffer overflow vulnerability in libbiosig's RHS2000 file parser allows arbitrary code execution when processing malicious files. This af...
Aug 25, 2025A heap-based buffer overflow vulnerability in Windows GDI+ allows remote attackers to execute arbitrary code on affected systems. This vulnerability a...
Aug 12, 2025A heap buffer overflow vulnerability in ExecuTorch's model loading functionality allows attackers to execute arbitrary code or cause denial of service...
Aug 7, 2025Multiple buffer overflow vulnerabilities in ExecuTorch model loading allow attackers to crash the runtime or potentially execute arbitrary code. This ...
Aug 7, 2025A heap-based buffer overflow vulnerability in Windows SPNEGO Extended Negotiation allows unauthenticated attackers to execute arbitrary code remotely ...
Jul 8, 2025This CVE describes a critical Bluetooth driver vulnerability allowing local privilege escalation without user interaction. An attacker with user-level...
Jul 8, 2025A critical buffer overflow vulnerability in ClamAV's PDF scanning allows remote attackers to crash the antivirus service or potentially execute arbitr...
Jun 18, 2025This CVE describes a critical Bluetooth driver vulnerability in MediaTek chipsets where an incorrect bounds check allows out-of-bounds write. Attacker...
Jun 2, 2025CVE-2025-40906 affects BSON::XS versions 0.8.4 and earlier for Perl, which bundle a vulnerable libbson 1.1.7 library containing multiple critical vuln...
May 16, 2025A heap-based buffer overflow vulnerability in Apache ORC's C++ LZO decompression logic allows attackers to cause memory corruption by providing specia...
May 14, 2025This CVE describes an integer overflow vulnerability in SQLite's concat_ws() function that leads to a heap buffer overflow. Attackers can exploit this...
Apr 14, 2025A critical heap buffer overflow vulnerability in CryptoLib versions 1.3.3 and prior allows attackers to cause denial of service or potentially execute...
Mar 17, 2025A heap-based buffer overflow vulnerability in SunGrow WiNet-SV200 MQTT message processing allows attackers to execute arbitrary code or cause denial o...
Jan 24, 2025A heap-based buffer overflow vulnerability in Siemens industrial software products allows unauthenticated remote attackers to execute arbitrary code. ...
Dec 16, 2024This vulnerability allows a malicious MQTT broker to crash or potentially execute arbitrary code on clients using libmosquitto by sending a specially ...
Oct 30, 2024CVE-2024-38812 is a critical heap-overflow vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. Attacke...
Sep 17, 2024A heap-based buffer overflow vulnerability in Samsung's Escargot JavaScript engine allows attackers to write beyond allocated memory boundaries. This ...
Sep 10, 2024A heap-based buffer overflow vulnerability in Siemens industrial software products allows unauthenticated remote attackers to execute arbitrary code. ...
Sep 10, 2024CVE-2024-32671 is a heap-based buffer overflow vulnerability in Samsung's Escargot JavaScript engine that allows attackers to execute arbitrary code o...
Jul 29, 2024This vulnerability allows unauthenticated attackers to execute arbitrary code on Windows systems running the Remote Desktop Licensing Service. It affe...
Jul 9, 2024A heap-based buffer overflow vulnerability in Fluent Bit's embedded HTTP server allows attackers to corrupt memory by sending specially crafted trace ...
May 20, 2024CVE-2024-32621 is a critical heap-based buffer overflow vulnerability in the HDF5 library that allows attackers to corrupt the instruction pointer and...
May 14, 2024About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 834 CVEs classified as CWE-122, with 106 rated critical and 649 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free