CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

852
Total CVEs
108
Critical
665
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 86
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (852)

CVE-2023-26394
7.8

Adobe Substance 3D Stager versions 2.0.1 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...

Apr 12, 2023
CVE-2022-45115
7.8

A buffer overflow vulnerability in Ichitaro 2022's Attribute Arena functionality allows memory corruption when processing malicious documents. Attacke...

Apr 5, 2023
CVE-2023-25895
7.8

Adobe Dimension versions 3.4.7 and earlier contain a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a...

Mar 28, 2023
CVE-2023-25897
7.8

CVE-2023-25897 is a heap-based buffer overflow vulnerability in Adobe Dimension versions 3.4.7 and earlier, allowing arbitrary code execution in the c...

Mar 28, 2023
CVE-2023-25883
7.8

CVE-2023-25883 is a heap-based buffer overflow vulnerability in Adobe Dimension that could allow attackers to execute arbitrary code on affected syste...

Mar 28, 2023
CVE-2023-25885
7.8

CVE-2023-25885 is a heap-based buffer overflow vulnerability in Adobe Dimension that could allow arbitrary code execution when a user opens a maliciou...

Mar 28, 2023
CVE-2023-1655
7.8

A heap-based buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or cause denial of service by proce...

Mar 27, 2023
CVE-2023-23782
7.8

This is a heap-based buffer overflow vulnerability in Fortinet FortiWeb web application firewalls that allows attackers to escalate privileges by send...

Feb 16, 2023
CVE-2023-23390
7.8

CVE-2023-23390 is a heap-based buffer overflow vulnerability in Microsoft 3D Builder that allows remote code execution. Attackers can exploit this by ...

Feb 14, 2023
CVE-2023-24550
7.8

A heap-based buffer overflow vulnerability in Solid Edge allows attackers to execute arbitrary code by tricking users into opening malicious PAR files...

Feb 14, 2023
CVE-2023-0819
7.8

This CVE describes a heap-based buffer overflow vulnerability in the GPAC multimedia framework. Attackers can exploit this to execute arbitrary code o...

Feb 13, 2023
CVE-2022-2522
7.8

CVE-2022-2522 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.0061. Attackers can exploit this by tricking user...

Jul 25, 2022
CVE-2022-1924
7.8

CVE-2022-1924 is an integer overflow vulnerability in the GStreamer multimedia framework's Matroska demuxer during LZO decompression. This can cause d...

Jul 19, 2022
CVE-2022-2122
7.8

This CVE describes an integer overflow vulnerability in the qtdemux element of GStreamer when processing zlib-compressed data. It can cause denial of ...

Jul 19, 2022
CVE-2022-1920
7.8

This CVE describes an integer overflow vulnerability in the matroskademux element of GStreamer's gst_matroska_demux_add_wvpk_header function. When par...

Jul 19, 2022
CVE-2022-1922
7.8

CVE-2022-1922 is an integer overflow vulnerability in GStreamer's Matroska demuxer that can cause denial of service or potential heap overwrite during...

Jul 19, 2022
CVE-2022-34245
7.8

Adobe InDesign versions 17.2.1 and earlier (and 16.4.1 and earlier) contain a heap-based buffer overflow vulnerability that could allow attackers to e...

Jul 15, 2022
CVE-2022-34249
7.8

CVE-2022-34249 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow attackers to execute arbitrary code when a user opens a ...

Jul 15, 2022
CVE-2022-34241
7.8

CVE-2022-34241 is a heap-based buffer overflow vulnerability in Adobe Character Animator that allows arbitrary code execution when a user opens a mali...

Jul 15, 2022
CVE-2022-2207
7.8

CVE-2022-2207 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 27, 2022
CVE-2022-2182
7.8

CVE-2022-2182 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 23, 2022
CVE-2022-2125
7.8

CVE-2022-2125 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jun 19, 2022
CVE-2022-30650
7.8

CVE-2022-30650 is a heap-based buffer overflow vulnerability in Adobe InCopy that allows arbitrary code execution when a user opens a malicious file. ...

Jun 16, 2022
CVE-2022-30654
7.8

CVE-2022-30654 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow attackers to execute arbitrary code on affected systems....

Jun 16, 2022
CVE-2022-30661
7.8

This heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. It affe...

Jun 16, 2022
CVE-2022-1733
7.8

CVE-2022-1733 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4968. Attackers can exploit this by tricking user...

May 17, 2022
CVE-2022-28234
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a mali...

May 11, 2022
CVE-2022-1619
7.8

CVE-2022-1619 is a heap-based buffer overflow vulnerability in Vim's command-line editing function that could allow attackers to crash the application...

May 8, 2022
CVE-2022-1381
7.8

CVE-2022-1381 is a heap buffer overflow vulnerability in Vim's skip_range function that allows attackers to crash the application, bypass memory prote...

Apr 18, 2022
CVE-2022-21214
7.8

This vulnerability allows attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects specific indu...

Apr 12, 2022
CVE-2022-1240
7.8

A heap buffer overflow vulnerability in radare2's Mach-O binary format parser allows attackers to execute arbitrary code or cause denial of service. T...

Apr 6, 2022
CVE-2022-0943
7.8

CVE-2022-0943 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2.4563. Attackers can exploit this by tricking user...

Mar 14, 2022
CVE-2022-24096
7.8

CVE-2022-24096 is a heap-based buffer overflow vulnerability in Adobe After Effects that allows arbitrary code execution when a user opens a malicious...

Mar 11, 2022
CVE-2022-0676
7.8

This CVE describes a heap-based buffer overflow vulnerability in radare2, a popular reverse engineering framework. Attackers can exploit this by provi...

Feb 22, 2022
CVE-2021-46647
7.8

CVE-2021-46647 is a heap-based buffer overflow vulnerability in Bentley MicroStation CONNECT's BMP image parser. Attackers can execute arbitrary code ...

Feb 18, 2022
CVE-2021-46603
7.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in Bentley MicroStation CONNECT's J2K ...

Feb 18, 2022
CVE-2021-46605
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Bentley MicroStation installations by tricking users into opening mal...

Feb 18, 2022
CVE-2021-21958
7.8

This heap-based buffer overflow vulnerability in Hancom Office's Hword component allows attackers to execute arbitrary code by tricking users into ope...

Feb 16, 2022
CVE-2021-44000
7.8

This vulnerability allows remote code execution through an out-of-bounds write in Siemens JT2Go, Solid Edge, and Teamcenter Visualization software whe...

Feb 9, 2022
CVE-2022-0417
7.8

CVE-2022-0417 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Feb 1, 2022
CVE-2022-0392
7.8

CVE-2022-0392 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...

Jan 28, 2022
CVE-2022-0361
7.8

CVE-2022-0361 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...

Jan 26, 2022
CVE-2022-0359
7.8

CVE-2022-0359 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This vulnerability allows attackers to execute a...

Jan 26, 2022
CVE-2021-44709
7.8

CVE-2021-44709 is a heap overflow vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution when a user opens a malicious PDF file...

Jan 14, 2022
CVE-2021-23157
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected WECON LeviStudioU systems by exploiting a heap-based buffer overflow....

Jan 14, 2022
CVE-2021-34945
7.8

CVE-2021-34945 is a heap-based buffer overflow vulnerability in Bentley View's JT file parser that allows remote code execution. Attackers can exploit...

Jan 13, 2022
CVE-2021-34905
7.8

CVE-2021-34905 is a heap-based buffer overflow vulnerability in Bentley View's DGN file parser that allows remote code execution. Attackers can exploi...

Jan 13, 2022
CVE-2021-34907
7.8

CVE-2021-34907 is a heap-based buffer overflow vulnerability in Bentley View's BMP file parser that allows remote code execution. Attackers can exploi...

Jan 13, 2022
CVE-2021-34893
7.8

CVE-2021-34893 is a heap-based buffer overflow vulnerability in Bentley View's BMP file parser that allows remote code execution. Attackers can exploi...

Jan 13, 2022
CVE-2021-4136
7.8

CVE-2021-4136 is a heap-based buffer overflow vulnerability in Vim that allows attackers to execute arbitrary code by tricking users into opening spec...

Dec 19, 2021

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 852 CVEs classified as CWE-122, with 108 rated critical and 665 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free