CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

848
Total CVEs
107
Critical
662
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (848)

CVE-2025-30330
7.8

A heap-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This af...

May 13, 2025
CVE-2025-29979
7.8

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users ...

May 13, 2025
CVE-2025-24063
7.8

A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...

May 13, 2025
CVE-2025-1045
7.8

A heap-based buffer overflow vulnerability in Luxion KeyShot Viewer allows remote attackers to execute arbitrary code when users open malicious KSP fi...

Apr 23, 2025
CVE-2025-1275
7.8

A heap-based buffer overflow vulnerability in Autodesk applications allows attackers to execute arbitrary code by tricking users into opening maliciou...

Apr 15, 2025
CVE-2025-1273
7.8

A heap-based buffer overflow vulnerability in Autodesk applications allows malicious PDF files to cause crashes, data leaks, or arbitrary code executi...

Apr 15, 2025
CVE-2025-30299
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability that allows arbitrary code execution when a us...

Apr 8, 2025
CVE-2025-30295
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...

Apr 8, 2025
CVE-2025-27490
7.8

A heap-based buffer overflow vulnerability in Windows Bluetooth Service allows authenticated attackers to execute arbitrary code with elevated SYSTEM ...

Apr 8, 2025
CVE-2025-27195
7.8

CVE-2025-27195 is a heap-based buffer overflow vulnerability in Adobe Media Encoder that could allow arbitrary code execution when a user opens a mali...

Apr 8, 2025
CVE-2025-27198
7.8

A heap-based buffer overflow vulnerability in Adobe Photoshop allows attackers to execute arbitrary code when a user opens a malicious file. This affe...

Apr 8, 2025
CVE-2025-27193
7.8

CVE-2025-27193 is a heap-based buffer overflow vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious f...

Apr 8, 2025
CVE-2025-26639
7.8

An integer overflow vulnerability in the Windows USB Print Driver allows authenticated attackers to execute arbitrary code with elevated privileges. T...

Apr 8, 2025
CVE-2025-2531
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious DAE file...

Mar 25, 2025
CVE-2025-1651
7.8

A heap-based buffer overflow vulnerability in Autodesk AutoCAD allows attackers to craft malicious MODEL files that can crash the application, leak se...

Mar 13, 2025
CVE-2025-1429
7.8

A heap-based buffer overflow vulnerability in Autodesk AutoCAD allows attackers to craft malicious MODEL files that can crash the application, leak se...

Mar 13, 2025
CVE-2025-2019
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Cobalt softwa...

Mar 11, 2025
CVE-2025-27173
7.8

CVE-2025-27173 is a heap-based buffer overflow vulnerability in Substance3D Modeler that allows arbitrary code execution when a user opens a malicious...

Mar 11, 2025
CVE-2025-24995
7.8

CVE-2025-24995 is a heap-based buffer overflow vulnerability in the Kernel Streaming WOW Thunk Service Driver that allows authenticated attackers to e...

Mar 11, 2025
CVE-2025-24993
KEV 7.8

A heap-based buffer overflow vulnerability in Windows NTFS allows local attackers to execute arbitrary code with elevated privileges. This affects Win...

Mar 11, 2025
CVE-2025-24985
KEV 7.8

An integer overflow vulnerability in the Windows Fast FAT driver allows local attackers to execute arbitrary code with elevated privileges. This affec...

Mar 11, 2025
CVE-2025-24066
7.8

A heap-based buffer overflow vulnerability in Windows Kernel-Mode Drivers allows authenticated attackers to execute arbitrary code with elevated SYSTE...

Mar 11, 2025
CVE-2025-24067
7.8

A heap-based buffer overflow vulnerability in Microsoft Streaming Service allows authenticated attackers to execute arbitrary code with elevated privi...

Mar 11, 2025
CVE-2025-24057
7.8

A heap-based buffer overflow vulnerability in Microsoft Office allows attackers to execute arbitrary code on vulnerable systems by tricking users into...

Mar 11, 2025
CVE-2025-24050
7.8

CVE-2025-24050 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows an authenticated attacker to execute arbitrary code with e...

Mar 11, 2025
CVE-2025-24048
7.8

CVE-2025-24048 is a heap-based buffer overflow vulnerability in Windows Hyper-V that allows authenticated attackers to execute arbitrary code with ele...

Mar 11, 2025
CVE-2025-21169
7.8

CVE-2025-21169 is a heap-based buffer overflow vulnerability in Substance3D Designer that could allow arbitrary code execution when a user opens a mal...

Mar 11, 2025
CVE-2025-21180
7.8

A heap-based buffer overflow vulnerability in the Windows exFAT file system driver allows local attackers to execute arbitrary code with elevated priv...

Mar 11, 2025
CVE-2025-22881
7.8

Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability (CWE-122) that allows remote code execution when users visit malicious pag...

Feb 26, 2025
CVE-2025-21418
KEV 7.8

This vulnerability in Windows Ancillary Function Driver for WinSock allows attackers to gain SYSTEM-level privileges by exploiting a heap-based buffer...

Feb 11, 2025
CVE-2025-21123
7.8

Adobe InDesign has a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects us...

Feb 11, 2025
CVE-2025-22880
7.8

Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability (CWE-122) that allows remote code execution when users visit malicious pag...

Feb 7, 2025
CVE-2025-21137
7.8

A heap-based buffer overflow vulnerability in Substance3D Designer versions 14.0 and earlier allows attackers to execute arbitrary code when a user op...

Jan 14, 2025
CVE-2025-21139
7.8

CVE-2025-21139 is a heap-based buffer overflow vulnerability in Substance3D Designer that allows arbitrary code execution when a user opens a maliciou...

Jan 14, 2025
CVE-2025-21129
7.8

A heap-based buffer overflow vulnerability in Substance3D Stager versions 3.0.4 and earlier allows attackers to execute arbitrary code with the privil...

Jan 14, 2025
CVE-2025-21395
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Access. Attackers can exploit...

Jan 14, 2025
CVE-2025-21378
7.8

This vulnerability in Windows CSC (Client Side Caching) Service allows local attackers to escalate privileges on affected systems. Attackers could gai...

Jan 14, 2025
CVE-2025-21382
7.8

This vulnerability in the Windows Graphics Component allows attackers to escalate privileges on affected systems. It affects Windows operating systems...

Jan 14, 2025
CVE-2025-21356
7.8

This vulnerability allows remote code execution when a user opens a specially crafted Visio file. Attackers could exploit this to run arbitrary code w...

Jan 14, 2025
CVE-2025-21333
KEV EPSS 72.9% 7.8

This vulnerability allows a local authenticated attacker to escalate privileges on Windows Hyper-V hosts by exploiting a heap-based buffer overflow in...

Jan 14, 2025
CVE-2025-21186
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Access. Attackers could explo...

Jan 14, 2025
CVE-2024-13051
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite. Att...

Dec 30, 2024
CVE-2024-12669
7.8

A heap-based buffer overflow vulnerability in Autodesk Navisworks allows attackers to craft malicious DWFX files that can crash the application, leak ...

Dec 17, 2024
CVE-2024-53957
7.8

A heap-based buffer overflow vulnerability in Substance3D Painter allows attackers to execute arbitrary code when a user opens a malicious file. This ...

Dec 10, 2024
CVE-2024-52999
7.8

CVE-2024-52999 is a heap-based buffer overflow vulnerability in Substance3D Modeler that allows arbitrary code execution when a user opens a malicious...

Dec 10, 2024
CVE-2024-52995
7.8

CVE-2024-52995 is a heap-based buffer overflow vulnerability in Adobe Substance3D Sampler that allows arbitrary code execution when a user opens a mal...

Dec 10, 2024
CVE-2024-49545
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on the victim's...

Dec 10, 2024
CVE-2024-54094
7.8

A heap-based buffer overflow vulnerability in Solid Edge SE2024 allows attackers to execute arbitrary code by tricking users into opening malicious PA...

Dec 10, 2024
CVE-2024-7508
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. At...

Nov 22, 2024
CVE-2024-9743
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...

Nov 22, 2024

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 848 CVEs classified as CWE-122, with 107 rated critical and 662 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free