CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (848)
A heap-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This af...
May 13, 2025A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users ...
May 13, 2025A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...
May 13, 2025A heap-based buffer overflow vulnerability in Luxion KeyShot Viewer allows remote attackers to execute arbitrary code when users open malicious KSP fi...
Apr 23, 2025A heap-based buffer overflow vulnerability in Autodesk applications allows attackers to execute arbitrary code by tricking users into opening maliciou...
Apr 15, 2025A heap-based buffer overflow vulnerability in Autodesk applications allows malicious PDF files to cause crashes, data leaks, or arbitrary code executi...
Apr 15, 2025Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability that allows arbitrary code execution when a us...
Apr 8, 2025Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...
Apr 8, 2025A heap-based buffer overflow vulnerability in Windows Bluetooth Service allows authenticated attackers to execute arbitrary code with elevated SYSTEM ...
Apr 8, 2025CVE-2025-27195 is a heap-based buffer overflow vulnerability in Adobe Media Encoder that could allow arbitrary code execution when a user opens a mali...
Apr 8, 2025A heap-based buffer overflow vulnerability in Adobe Photoshop allows attackers to execute arbitrary code when a user opens a malicious file. This affe...
Apr 8, 2025CVE-2025-27193 is a heap-based buffer overflow vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious f...
Apr 8, 2025An integer overflow vulnerability in the Windows USB Print Driver allows authenticated attackers to execute arbitrary code with elevated privileges. T...
Apr 8, 2025This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious DAE file...
Mar 25, 2025A heap-based buffer overflow vulnerability in Autodesk AutoCAD allows attackers to craft malicious MODEL files that can crash the application, leak se...
Mar 13, 2025A heap-based buffer overflow vulnerability in Autodesk AutoCAD allows attackers to craft malicious MODEL files that can crash the application, leak se...
Mar 13, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Cobalt softwa...
Mar 11, 2025CVE-2025-27173 is a heap-based buffer overflow vulnerability in Substance3D Modeler that allows arbitrary code execution when a user opens a malicious...
Mar 11, 2025CVE-2025-24995 is a heap-based buffer overflow vulnerability in the Kernel Streaming WOW Thunk Service Driver that allows authenticated attackers to e...
Mar 11, 2025A heap-based buffer overflow vulnerability in Windows NTFS allows local attackers to execute arbitrary code with elevated privileges. This affects Win...
Mar 11, 2025An integer overflow vulnerability in the Windows Fast FAT driver allows local attackers to execute arbitrary code with elevated privileges. This affec...
Mar 11, 2025A heap-based buffer overflow vulnerability in Windows Kernel-Mode Drivers allows authenticated attackers to execute arbitrary code with elevated SYSTE...
Mar 11, 2025A heap-based buffer overflow vulnerability in Microsoft Streaming Service allows authenticated attackers to execute arbitrary code with elevated privi...
Mar 11, 2025A heap-based buffer overflow vulnerability in Microsoft Office allows attackers to execute arbitrary code on vulnerable systems by tricking users into...
Mar 11, 2025CVE-2025-24050 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authenticated attacker to execute arbitrary code with e...
Mar 11, 2025CVE-2025-24048 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows authenticated attackers to execute arbitrary code with ele...
Mar 11, 2025CVE-2025-21169 is a heap-based buffer overflow vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a mal...
Mar 11, 2025A heap-based buffer overflow vulnerability in the Windows exFAT file system driver allows local attackers to execute arbitrary code with elevated priv...
Mar 11, 2025Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability (CWE-122) that allows remote code execution when users visit malicious pag...
Feb 26, 2025This vulnerability in Windows Ancillary Function Driver for WinSock allows attackers to gain SYSTEM-level privileges by exploiting a heap-based buffer...
Feb 11, 2025Adobe InDesign has a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects us...
Feb 11, 2025Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability (CWE-122) that allows remote code execution when users visit malicious pag...
Feb 7, 2025A heap-based buffer overflow vulnerability in Substance3D Designer versions 14.0 and earlier allows attackers to execute arbitrary code when a user op...
Jan 14, 2025CVE-2025-21139 is a heap-based buffer overflow vulnerability in Substance3D Designer that allows arbitrary code execution when a user opens a maliciou...
Jan 14, 2025A heap-based buffer overflow vulnerability in Substance3D Stager versions 3.0.4 and earlier allows attackers to execute arbitrary code with the privil...
Jan 14, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Access. Attackers can exploit...
Jan 14, 2025This vulnerability in Windows CSC (Client Side Caching) Service allows local attackers to escalate privileges on affected systems. Attackers could gai...
Jan 14, 2025This vulnerability in the Windows Graphics Component allows attackers to escalate privileges on affected systems. It affects Windows operating systems...
Jan 14, 2025This vulnerability allows remote code execution when a user opens a specially crafted Visio file. Attackers could exploit this to run arbitrary code w...
Jan 14, 2025This vulnerability allows a local authenticated attacker to escalate privileges on Windows Hyper-V hosts by exploiting a heap-based buffer overflow in...
Jan 14, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Access. Attackers could explo...
Jan 14, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite. Att...
Dec 30, 2024A heap-based buffer overflow vulnerability in Autodesk Navisworks allows attackers to craft malicious DWFX files that can crash the application, leak ...
Dec 17, 2024A heap-based buffer overflow vulnerability in Substance3D Painter allows attackers to execute arbitrary code when a user opens a malicious file. This ...
Dec 10, 2024CVE-2024-52999 is a heap-based buffer overflow vulnerability in Substance3D Modeler that allows arbitrary code execution when a user opens a malicious...
Dec 10, 2024CVE-2024-52995 is a heap-based buffer overflow vulnerability in Adobe Substance3D Sampler that allows arbitrary code execution when a user opens a mal...
Dec 10, 2024This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on the victim's...
Dec 10, 2024A heap-based buffer overflow vulnerability in Solid Edge SE2024 allows attackers to execute arbitrary code by tricking users into opening malicious PA...
Dec 10, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. At...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...
Nov 22, 2024About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 848 CVEs classified as CWE-122, with 107 rated critical and 662 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free