CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (850)
This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Tungsten Automation Power P...
Nov 22, 2024A heap-based buffer overflow vulnerability in Tungsten Automation Power PDF allows remote attackers to execute arbitrary code when a user opens a mali...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView by tricking users into openin...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening a malicious XCF file in IrfanView. Attackers can e...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ECW image files in IrfanView. Attackers ...
Nov 22, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in IrfanView. Attackers can ga...
Nov 22, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious X_B or SAT files in eDrawings. It affects users...
Nov 19, 2024This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privil...
Nov 12, 2024This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code on a victim's s...
Nov 12, 2024CVE-2024-49525 is a heap-based buffer overflow vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a mali...
Nov 12, 2024CVE-2024-49517 is a heap-based buffer overflow vulnerability in Substance3D Painter that could allow arbitrary code execution when a user opens a mali...
Nov 12, 2024Substance3D Painter versions 10.1.0 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrary cod...
Nov 12, 2024Adobe Illustrator versions 28.7.1 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user...
Nov 12, 2024This vulnerability in the X.org server allows local attackers to trigger a buffer overflow via a specially crafted payload. This could lead to denial ...
Oct 30, 2024A heap-based buffer overflow vulnerability in Autodesk AutoCAD's libodxdll.dll allows attackers to execute arbitrary code by tricking users into openi...
Oct 29, 2024A heap-based buffer overflow vulnerability in Autodesk AutoCAD's odxsw_dll.dll allows attackers to execute arbitrary code by tricking users into openi...
Oct 29, 2024CVE-2024-45143 is a heap-based buffer overflow vulnerability in Adobe Substance3D Stager that could allow arbitrary code execution when a user opens a...
Oct 9, 2024CVE-2024-45139 is a heap-based buffer overflow vulnerability in Adobe Substance3D Stager that allows arbitrary code execution when a user opens a mali...
Oct 9, 2024This vulnerability in the Microsoft Windows Storage Port Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It ...
Oct 8, 2024This Windows kernel vulnerability allows attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows s...
Oct 8, 2024A heap-based buffer overflow vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking users into opening malicious BDF ...
Oct 8, 2024A heap buffer overflow vulnerability in Chrome's PDF renderer allows remote attackers to execute arbitrary code or cause denial of service via special...
Sep 23, 2024CVE-2024-43756 is a heap-based buffer overflow vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a maliciou...
Sep 13, 2024This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a heap-based buffer overflow in the Kernel Streaming ...
Sep 10, 2024This is a Windows kernel driver vulnerability in the Kernel Streaming Service that allows local attackers to escalate privileges from a low-privileged...
Sep 10, 2024CVE-2024-41853 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow arbitrary code execution when a user opens a malicious...
Aug 14, 2024This vulnerability allows remote code execution through specially crafted Excel files. Attackers can exploit this by tricking users into opening malic...
Aug 13, 2024This vulnerability allows an attacker with local access to elevate privileges from user mode to kernel mode in Windows Secure Kernel. It affects Windo...
Aug 13, 2024This vulnerability allows local attackers to execute arbitrary code with elevated privileges on oFono installations by exploiting a heap-based buffer ...
Aug 6, 2024This heap-based buffer overflow vulnerability in oFono's SimToolKit (STK) command parser allows local attackers with initial code execution on the tar...
Aug 6, 2024A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of...
Aug 2, 2024A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users ru...
Jul 9, 2024This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a heap-b...
Jul 9, 2024This vulnerability in the Windows Kernel Streaming WOW Thunk Service Driver allows an authenticated attacker to execute arbitrary code with SYSTEM pri...
Jul 9, 2024This vulnerability allows attackers to exploit a heap-based buffer overflow in Autodesk applications when processing malicious SLDPRT files. Attackers...
Jun 25, 2024CVE-2024-30091 is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a ...
Jun 11, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...
Jun 11, 2024This vulnerability in the Windows Cloud Files Mini Filter Driver allows an authenticated attacker to gain SYSTEM-level privileges on affected systems....
Jun 11, 2024A heap-based buffer overflow vulnerability in Kofax Power PDF's PSD file parser allows remote attackers to execute arbitrary code when a user opens a ...
Jun 6, 2024This vulnerability allows a low-privilege local user with the Ivanti EPM Agent installed to exploit a buffer overflow and execute arbitrary code with ...
May 31, 2024This CVE describes a heap-based buffer overflow vulnerability in Adobe Framemaker that could allow an attacker to execute arbitrary code on a victim's...
May 16, 2024Adobe Animate versions 24.0.2, 23.0.5 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrary c...
May 16, 2024This vulnerability in the Windows Desktop Window Manager (DWM) Core Library allows an attacker to gain elevated privileges on a system, potentially en...
May 14, 2024This is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a compromise...
May 14, 2024A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...
May 14, 2024A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...
May 14, 2024A heap-based buffer overflow vulnerability in Bentley View's FBX file parser allows remote attackers to execute arbitrary code when users open malicio...
May 7, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Foxit PDF Reader installations by tricking users into opening malicio...
May 7, 2024This vulnerability allows remote attackers to execute arbitrary code on vulnerable GIMP installations by tricking users into opening malicious DDS ima...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...
May 3, 2024About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 850 CVEs classified as CWE-122, with 107 rated critical and 664 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free