CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

851
Total CVEs
108
Critical
664
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (851)

CVE-2023-42085
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...

May 3, 2024
CVE-2023-42076
7.8

This is a heap-based buffer overflow vulnerability in PDF-XChange Editor's PDF file parsing functionality. Attackers can execute arbitrary code by tri...

May 3, 2024
CVE-2023-42038
7.8

A heap-based buffer overflow vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code when users open malicious PDF files. T...

May 3, 2024
CVE-2023-39492
7.8

A heap-based buffer overflow vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code when users open malicious PDF files...

May 3, 2024
CVE-2023-39494
7.8

A heap-based buffer overflow vulnerability in PDF-XChange Editor's OXPS file parser allows remote attackers to execute arbitrary code when users open ...

May 3, 2024
CVE-2023-37335
7.8

A heap-based buffer overflow vulnerability in Kofax Power PDF's BMP file parser allows remote attackers to execute arbitrary code when a user opens a ...

May 3, 2024
CVE-2023-34299
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files in Ashlar-Vellum Cobalt. Attack...

May 3, 2024
CVE-2023-34289
7.8

This is a heap-based buffer overflow vulnerability in Ashlar-Vellum Cobalt's AR file parser that allows remote code execution. Attackers can exploit i...

May 3, 2024
CVE-2023-51794
7.8

A buffer overflow vulnerability in FFmpeg's stereowiden audio filter allows local attackers to execute arbitrary code by providing specially crafted a...

Apr 26, 2024
CVE-2024-26256
7.8

CVE-2024-26256 is a heap-based buffer overflow vulnerability in Libarchive that allows remote attackers to execute arbitrary code by crafting maliciou...

Apr 9, 2024
CVE-2024-26229
7.8

This vulnerability in the Windows Client Side Caching (CSC) service allows an authenticated attacker to execute arbitrary code with SYSTEM privileges....

Apr 9, 2024
CVE-2024-27341
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files in Kofax Power PDF. Attackers ...

Apr 3, 2024
CVE-2024-1848
7.8

Multiple memory corruption vulnerabilities in SOLIDWORKS Desktop 2024 allow arbitrary code execution when opening malicious CAD files. Attackers can e...

Mar 22, 2024
CVE-2024-20745
7.8

A heap-based buffer overflow vulnerability in Adobe Premiere Pro allows attackers to execute arbitrary code when a user opens a malicious file. This a...

Mar 18, 2024
CVE-2024-26540
7.8

A heap-based buffer overflow vulnerability in CImg library versions before 3.3.3 allows attackers to execute arbitrary code or cause denial of service...

Mar 15, 2024
CVE-2024-26178
7.8

This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a heap-based buffer ...

Mar 12, 2024
CVE-2024-21330
7.8

CVE-2024-21330 is an elevation of privilege vulnerability in Microsoft's Open Management Infrastructure (OMI) that allows authenticated attackers to e...

Mar 12, 2024
CVE-2024-1847
7.8

Multiple memory corruption vulnerabilities in eDrawings (SOLIDWORKS 2023-2024) allow arbitrary code execution when opening malicious CAD files. Attack...

Feb 28, 2024
CVE-2024-21885
7.8

This vulnerability in X.Org server allows heap buffer overflow when processing device hierarchy events. It can lead to application crashes or remote c...

Feb 28, 2024
CVE-2023-21740
7.8

CVE-2023-21740 is a heap-based buffer overflow vulnerability in Windows Media components that allows remote code execution. An attacker could exploit ...

Dec 12, 2023
CVE-2023-47056
7.8

This heap-based buffer overflow vulnerability in Adobe Premiere Pro allows attackers to execute arbitrary code when a user opens a malicious file. The...

Nov 16, 2023
CVE-2023-47042
7.8

A heap-based buffer overflow vulnerability in Adobe Media Encoder allows attackers to execute arbitrary code when a user opens a malicious file. This ...

Nov 16, 2023
CVE-2023-36598
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft's WDAC ODBC Driver by exploiting a heap-based buffer o...

Oct 10, 2023
CVE-2023-43787
7.8

This vulnerability in libX11's XCreateImage() function allows local users to trigger an integer overflow, potentially leading to arbitrary code execut...

Oct 10, 2023
CVE-2023-4911
KEV EPSS 63.6% 7.8

CVE-2023-4911 is a buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so) that allows local attackers to exploit SUID binaries. B...

Oct 3, 2023
CVE-2023-38143
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain SYSTEM-level privileges on affected systems. It affect...

Sep 12, 2023
CVE-2023-36793
7.8

This vulnerability allows remote code execution in Visual Studio when processing specially crafted files. Attackers could exploit this to run arbitrar...

Sep 12, 2023
CVE-2023-36770
7.8

CVE-2023-36770 is a heap-based buffer overflow vulnerability in Microsoft 3D Builder that allows remote code execution when processing specially craft...

Sep 12, 2023
CVE-2023-36772
7.8

CVE-2023-36772 is a heap-based buffer overflow vulnerability in Microsoft 3D Builder that allows remote code execution when processing specially craft...

Sep 12, 2023
CVE-2023-36739
7.8

CVE-2023-36739 is a heap-based buffer overflow vulnerability in Microsoft 3D Viewer that allows remote code execution when a user opens a specially cr...

Sep 12, 2023
CVE-2023-38071
7.8

This vulnerability allows remote code execution through heap-based buffer overflow when parsing malicious WRL files in Siemens JT2Go, Teamcenter Visua...

Sep 12, 2023
CVE-2023-4751
7.8

CVE-2023-4751 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.1331. Attackers can exploit this by tricking user...

Sep 3, 2023
CVE-2023-38154
7.8

This Windows kernel vulnerability allows local attackers to escalate privileges by exploiting memory corruption in the recovery process. It affects Wi...

Aug 8, 2023
CVE-2023-36865
7.8

This vulnerability allows remote code execution when a user opens a specially crafted Visio file. Attackers can exploit this to run arbitrary code wit...

Aug 8, 2023
CVE-2023-35374
7.8

This vulnerability in Paint 3D allows remote attackers to execute arbitrary code on affected systems by tricking users into opening specially crafted ...

Jul 11, 2023
CVE-2023-35363
7.8

This Windows kernel vulnerability allows attackers to elevate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows op...

Jul 11, 2023
CVE-2023-35337
7.8

This is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to execute arbitrary code with SYSTEM privilege...

Jul 11, 2023
CVE-2023-35304
7.8

This Windows kernel vulnerability allows attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows o...

Jul 11, 2023
CVE-2023-37246
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting a heap-based buffer overflow when parsing malicious PRT files in Tecnomati...

Jul 11, 2023
CVE-2023-34432
7.8

A heap buffer overflow vulnerability in sox's lsx_readbuf function allows attackers to write beyond allocated memory boundaries. This can lead to deni...

Jul 10, 2023
CVE-2023-34318
7.8

A heap buffer overflow vulnerability in sox's hcom.c file allows attackers to write beyond allocated memory boundaries. This can lead to denial of ser...

Jul 10, 2023
CVE-2023-27390
7.8

A heap-based buffer overflow vulnerability in Diagon's Sequence::DrawText function allows arbitrary code execution when processing malicious markdown ...

Jul 5, 2023
CVE-2023-32026
7.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code by sending specially crafted requests to ...

Jun 16, 2023
CVE-2023-32028
7.8

This vulnerability in Microsoft SQL OLE DB allows authenticated attackers to execute arbitrary code on affected SQL Server instances by sending specia...

Jun 16, 2023
CVE-2023-33146
7.8

CVE-2023-33146 is a heap-based buffer overflow vulnerability in Microsoft Office that allows remote code execution when a user opens a specially craft...

Jun 14, 2023
CVE-2023-33133
7.8

CVE-2023-33133 is a heap-based buffer overflow vulnerability in Microsoft Excel that allows remote code execution when a user opens a specially crafte...

Jun 14, 2023
CVE-2023-29370
7.8

CVE-2023-29370 is a heap-based buffer overflow vulnerability in Windows Media components that allows remote code execution. An attacker could exploit ...

Jun 14, 2023
CVE-2023-24014
7.8

Delta Electronics CNCSoft-B DOPSoft versions 1.0.0.4 and prior contain a heap-based buffer overflow vulnerability that could allow remote attackers to...

Jun 7, 2023
CVE-2023-29344
7.8

This vulnerability allows remote code execution through specially crafted Office documents. Attackers can exploit it by tricking users into opening ma...

Jun 5, 2023
CVE-2023-26413
7.8

Adobe Substance 3D Designer versions 12.4.0 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary ...

Apr 13, 2023

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 851 CVEs classified as CWE-122, with 108 rated critical and 664 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free