CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

850
Total CVEs
107
Critical
664
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (850)

CVE-2024-9743
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...

Nov 22, 2024
CVE-2024-9741
7.8

A heap-based buffer overflow vulnerability in Tungsten Automation Power PDF allows remote attackers to execute arbitrary code when a user opens a mali...

Nov 22, 2024
CVE-2024-11509
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView by tricking users into openin...

Nov 22, 2024
CVE-2024-11511
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening a malicious XCF file in IrfanView. Attackers can e...

Nov 22, 2024
CVE-2024-11513
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ECW image files in IrfanView. Attackers ...

Nov 22, 2024
CVE-2024-6816
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-10204
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious X_B or SAT files in eDrawings. It affects users...

Nov 19, 2024
CVE-2024-49509
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privil...

Nov 12, 2024
CVE-2024-49507
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's s...

Nov 12, 2024
CVE-2024-49525
7.8

CVE-2024-49525 is a heap-based buffer overflow vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Nov 12, 2024
CVE-2024-49517
7.8

CVE-2024-49517 is a heap-based buffer overflow vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a mali...

Nov 12, 2024
CVE-2024-47431
7.8

Substance3D Painter versions 10.1.0 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrary cod...

Nov 12, 2024
CVE-2024-47450
7.8

Adobe Illustrator versions 28.7.1 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user...

Nov 12, 2024
CVE-2024-9632
7.8

This vulnerability in the X.org server allows local attackers to trigger a buffer overflow via a specially crafted payload. This could lead to denial ...

Oct 30, 2024
CVE-2024-8594
7.8

A heap-based buffer overflow vulnerability in Autodesk AutoCAD's libodxdll.dll allows attackers to execute arbitrary code by tricking users into openi...

Oct 29, 2024
CVE-2024-8587
7.8

A heap-based buffer overflow vulnerability in Autodesk AutoCAD's odxsw_dll.dll allows attackers to execute arbitrary code by tricking users into openi...

Oct 29, 2024
CVE-2024-45143
7.8

CVE-2024-45143 is a heap-based buffer overflow vulnerability in Adobe Substance3D Stager that could allow arbitrary code execution when a user opens a...

Oct 9, 2024
CVE-2024-45139
7.8

CVE-2024-45139 is a heap-based buffer overflow vulnerability in Adobe Substance3D Stager that allows arbitrary code execution when a user opens a mali...

Oct 9, 2024
CVE-2024-43560
7.8

This vulnerability in the Microsoft Windows Storage Port Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It ...

Oct 8, 2024
CVE-2024-43527
7.8

This Windows kernel vulnerability allows attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows s...

Oct 8, 2024
CVE-2024-41981
7.8

A heap-based buffer overflow vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious BDF ...

Oct 8, 2024
CVE-2024-7018
7.8

A heap buffer overflow vulnerability in Chrome's PDF renderer allows remote attackers to execute arbitrary code or cause denial of service via special...

Sep 23, 2024
CVE-2024-43756
7.8

CVE-2024-43756 is a heap-based buffer overflow vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a maliciou...

Sep 13, 2024
CVE-2024-38242
7.8

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a heap-based buffer overflow in the Kernel Streaming ...

Sep 10, 2024
CVE-2024-38238
7.8

This is a Windows kernel driver vulnerability in the Kernel Streaming Service that allows local attackers to escalate privileges from a low-privileged...

Sep 10, 2024
CVE-2024-41853
7.8

CVE-2024-41853 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious...

Aug 14, 2024
CVE-2024-38172
7.8

This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malic...

Aug 13, 2024
CVE-2024-38142
7.8

This vulnerability allows an attacker with local access to elevate privileges from user mode to kernel mode in Windows Secure Kernel. It affects Windo...

Aug 13, 2024
CVE-2024-7545
7.8

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on oFono installations by exploiting a heap-based buffer ...

Aug 6, 2024
CVE-2024-7543
7.8

This heap-based buffer overflow vulnerability in oFono's SimToolKit (STK) command parser allows local attackers with initial code execution on the tar...

Aug 6, 2024
CVE-2024-39392
7.8

A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of...

Aug 2, 2024
CVE-2024-20785
7.8

A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users ru...

Jul 9, 2024
CVE-2024-38079
7.8

This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a heap-b...

Jul 9, 2024
CVE-2024-38054
7.8

This vulnerability in the Windows Kernel Streaming WOW Thunk Service Driver allows an authenticated attacker to execute arbitrary code with SYSTEM pri...

Jul 9, 2024
CVE-2024-23154
7.8

This vulnerability allows attackers to exploit a heap-based buffer overflow in Autodesk applications when processing malicious SLDPRT files. Attackers...

Jun 25, 2024
CVE-2024-30091
7.8

CVE-2024-30091 is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a ...

Jun 11, 2024
CVE-2024-30094
7.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...

Jun 11, 2024
CVE-2024-30085
7.8

This vulnerability in the Windows Cloud Files Mini Filter Driver allows an authenticated attacker to gain SYSTEM-level privileges on affected systems....

Jun 11, 2024
CVE-2024-5301
7.8

A heap-based buffer overflow vulnerability in Kofax Power PDF's PSD file parser allows remote attackers to execute arbitrary code when a user opens a ...

Jun 6, 2024
CVE-2024-22058
7.8

This vulnerability allows a low-privilege local user with the Ivanti EPM Agent installed to exploit a buffer overflow and execute arbitrary code with ...

May 31, 2024
CVE-2024-30288
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe Framemaker that could allow an attacker to execute arbitrary code on a victim's...

May 16, 2024
CVE-2024-30294
7.8

Adobe Animate versions 24.0.2, 23.0.5 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrary c...

May 16, 2024
CVE-2024-30051
7.8

This vulnerability in the Windows Desktop Window Manager (DWM) Core Library allows an attacker to gain elevated privileges on a system, potentially en...

May 14, 2024
CVE-2024-30038
7.8

This is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a compromise...

May 14, 2024
CVE-2024-34771
7.8

A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...

May 14, 2024
CVE-2024-33489
7.8

A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...

May 14, 2024
CVE-2022-43655
7.8

A heap-based buffer overflow vulnerability in Bentley View's FBX file parser allows remote attackers to execute arbitrary code when users open malicio...

May 7, 2024
CVE-2021-34971
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Foxit PDF Reader installations by tricking users into opening malicio...

May 7, 2024
CVE-2023-44441
7.8

This vulnerability allows remote attackers to execute arbitrary code on vulnerable GIMP installations by tricking users into opening malicious DDS ima...

May 3, 2024
CVE-2023-42085
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 850 CVEs classified as CWE-122, with 107 rated critical and 664 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free