CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (852)
Adobe Substance 3D Stager versions 2.0.1 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...
Apr 12, 2023A buffer overflow vulnerability in Ichitaro 2022's Attribute Arena functionality allows memory corruption when processing malicious documents. Attacke...
Apr 5, 2023Adobe Dimension versions 3.4.7 and earlier contain a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a...
Mar 28, 2023CVE-2023-25897 is a heap-based buffer overflow vulnerability in Adobe Dimension versions 3.4.7 and earlier, allowing arbitrary code execution in the c...
Mar 28, 2023CVE-2023-25883 is a heap-based buffer overflow vulnerability in Adobe Dimension that could allow attackers to execute arbitrary code on affected syste...
Mar 28, 2023CVE-2023-25885 is a heap-based buffer overflow vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a maliciou...
Mar 28, 2023A heap-based buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or cause denial of service by proce...
Mar 27, 2023This is a heap-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls that allows attackers to escalate privileges by send...
Feb 16, 2023CVE-2023-23390 is a heap-based buffer overflow vulnerability in Microsoft 3D Builder that allows remote code execution. Attackers can exploit this by ...
Feb 14, 2023A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...
Feb 14, 2023This CVE describes a heap-based buffer overflow vulnerability in the GPAC multimedia framework. Attackers can exploit this to execute arbitrary code o...
Feb 13, 2023CVE-2022-2522 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.0061. Attackers can exploit this by tricking user...
Jul 25, 2022CVE-2022-1924 is an integer overflow vulnerability in the GStreamer multimedia framework's Matroska demuxer during LZO decompression. This can cause d...
Jul 19, 2022This CVE describes an integer overflow vulnerability in the qtdemux element of GStreamer when processing zlib-compressed data. It can cause denial of ...
Jul 19, 2022This CVE describes an integer overflow vulnerability in the matroskademux element of GStreamer's gst_matroska_demux_add_wvpk_header function. When par...
Jul 19, 2022CVE-2022-1922 is an integer overflow vulnerability in GStreamer's Matroska demuxer that can cause denial of service or potential heap overwrite during...
Jul 19, 2022Adobe InDesign versions 17.2.1 and earlier (and 16.4.1 and earlier) contain a heap-based buffer overflow vulnerability that could allow attackers to e...
Jul 15, 2022CVE-2022-34249 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow attackers to execute arbitrary code when a user opens a ...
Jul 15, 2022CVE-2022-34241 is a heap-based buffer overflow vulnerability in Adobe Character Animator that allows arbitrary code execution when a user opens a mali...
Jul 15, 2022CVE-2022-2207 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...
Jun 27, 2022CVE-2022-2182 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...
Jun 23, 2022CVE-2022-2125 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...
Jun 19, 2022CVE-2022-30650 is a heap-based buffer overflow vulnerability in Adobe InCopy that allows arbitrary code execution when a user opens a malicious file. ...
Jun 16, 2022CVE-2022-30654 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow attackers to execute arbitrary code on affected systems....
Jun 16, 2022This heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. It affe...
Jun 16, 2022CVE-2022-1733 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4968. Attackers can exploit this by tricking user...
May 17, 2022This CVE describes a heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a mali...
May 11, 2022CVE-2022-1619 is a heap-based buffer overflow vulnerability in Vim's command-line editing function that could allow attackers to crash the application...
May 8, 2022CVE-2022-1381 is a heap buffer overflow vulnerability in Vim's skip_range function that allows attackers to crash the application, bypass memory prote...
Apr 18, 2022This vulnerability allows attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects specific indu...
Apr 12, 2022A heap buffer overflow vulnerability in radare2's Mach-O binary format parser allows attackers to execute arbitrary code or cause denial of service. T...
Apr 6, 2022CVE-2022-0943 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4563. Attackers can exploit this by tricking user...
Mar 14, 2022CVE-2022-24096 is a heap-based buffer overflow vulnerability in Adobe After Effects that allows arbitrary code execution when a user opens a malicious...
Mar 11, 2022This CVE describes a heap-based buffer overflow vulnerability in radare2, a popular reverse engineering framework. Attackers can exploit this by provi...
Feb 22, 2022CVE-2021-46647 is a heap-based buffer overflow vulnerability in Bentley MicroStation CONNECT's BMP image parser. Attackers can execute arbitrary code ...
Feb 18, 2022This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in Bentley MicroStation CONNECT's J2K ...
Feb 18, 2022This vulnerability allows remote attackers to execute arbitrary code on affected Bentley MicroStation installations by tricking users into opening mal...
Feb 18, 2022This heap-based buffer overflow vulnerability in Hancom Office's Hword component allows attackers to execute arbitrary code by tricking users into ope...
Feb 16, 2022This vulnerability allows remote code execution through an out-of-bounds write in Siemens JT2Go, Solid Edge, and Teamcenter Visualization software whe...
Feb 9, 2022CVE-2022-0417 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...
Feb 1, 2022CVE-2022-0392 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...
Jan 28, 2022CVE-2022-0361 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...
Jan 26, 2022CVE-2022-0359 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...
Jan 26, 2022CVE-2021-44709 is a heap overflow vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF file...
Jan 14, 2022This vulnerability allows remote attackers to execute arbitrary code on affected WECON LeviStudioU systems by exploiting a heap-based buffer overflow....
Jan 14, 2022CVE-2021-34945 is a heap-based buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit...
Jan 13, 2022CVE-2021-34905 is a heap-based buffer overflow vulnerability in Bentley View's DGN file parser that allows remote code execution. Attackers can exploi...
Jan 13, 2022CVE-2021-34907 is a heap-based buffer overflow vulnerability in Bentley View's BMP file parser that allows remote code execution. Attackers can exploi...
Jan 13, 2022CVE-2021-34893 is a heap-based buffer overflow vulnerability in Bentley View's BMP file parser that allows remote code execution. Attackers can exploi...
Jan 13, 2022CVE-2021-4136 is a heap-based buffer overflow vulnerability in Vim that allows attackers to execute arbitrary code by tricking users into opening spec...
Dec 19, 2021About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 852 CVEs classified as CWE-122, with 108 rated critical and 665 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free