CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (855)
This vulnerability allows remote code execution through specially crafted JT files in Siemens JT Utilities and JTTK libraries. Attackers can exploit a...
Dec 14, 2021CVE-2021-4019 is a heap-based buffer overflow vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into ...
Dec 1, 2021A buffer overflow vulnerability in Adobe Acrobat Reader DC allows arbitrary code execution when a user opens a malicious PDF file. Attackers can explo...
Sep 29, 2021This vulnerability in Adobe SVG Native Viewer allows attackers to execute arbitrary code by tricking users into opening a malicious SVG file. It affec...
Sep 27, 2021CVE-2021-3778 is a heap-based buffer overflow vulnerability in Vim text editor that could allow attackers to execute arbitrary code or cause denial of...
Sep 15, 2021CVE-2021-3770 is a heap-based buffer overflow vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into ...
Sep 6, 2021CVE-2021-36050 is a heap-based buffer overflow vulnerability in Adobe XMP Toolkit SDK that could allow arbitrary code execution when processing malici...
Sep 1, 2021This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of Delta Electronics TPEditor by tricking users i...
Aug 30, 2021Adobe Animate versions 21.0.6 and earlier contain a heap-based buffer overflow vulnerability that allows arbitrary code execution when a user opens a ...
Aug 24, 2021CVE-2021-28610 is a heap-based buffer overflow vulnerability in Adobe After Effects that allows arbitrary code execution when a user opens a malicious...
Aug 24, 2021Adobe After Effects versions 18.2 and earlier contain a heap-based buffer overflow vulnerability when parsing malicious files. An attacker can exploit...
Aug 24, 2021CVE-2021-28608 is a heap-based buffer overflow vulnerability in Adobe After Effects that allows arbitrary code execution when a malicious file is open...
Aug 24, 2021This heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC allows attackers to execute arbitrary code on affected systems. An unauthenti...
Aug 20, 2021This vulnerability allows attackers to execute arbitrary code by exploiting a heap buffer overflow in Siemens JT2Go, Solid Edge SE2021, and Teamcenter...
Jul 13, 2021This vulnerability allows remote code execution through specially crafted PCX files in Siemens JT2Go and Teamcenter Visualization software. Attackers ...
Jul 13, 2021This vulnerability allows attackers to execute arbitrary code by exploiting a heap buffer overflow in Siemens JT2Go, Solid Edge SE2021, and Teamcenter...
Jul 13, 2021This vulnerability allows remote code execution through specially crafted TIFF files in Siemens JT2Go and Teamcenter Visualization software. Attackers...
Jul 13, 2021This vulnerability allows remote code execution through a specially crafted AMF file in PrusaSlicer. Attackers can exploit an out-of-bounds write in t...
Jul 8, 2021This heap-based buffer overflow vulnerability in SoftMaker Office PlanMaker 2021 allows attackers to execute arbitrary code by tricking victims into o...
Feb 23, 2021This is a heap-based buffer overflow vulnerability in SoftMaker Office PlanMaker 2021 that allows remote code execution when a user opens a specially ...
Feb 10, 2021A heap-based buffer overflow vulnerability in SoftMaker Office PlanMaker 2021 allows attackers to execute arbitrary code by tricking victims into open...
Feb 4, 2021This heap-based buffer overflow vulnerability in SoftMaker Office PlanMaker 2021 allows attackers to execute arbitrary code by tricking victims into o...
Feb 4, 2021This vulnerability is a heap-buffer overflow in openjpeg2's PNG file handling that allows attackers to crash applications or potentially execute arbit...
Jan 26, 2021This vulnerability is a heap buffer overflow in the Xorg X11 server's XkbSetDeviceInfo function. It allows local attackers to potentially escalate pri...
Dec 15, 2020A heap-based buffer overflow vulnerability in WECON LeviStudioU allows attackers to execute arbitrary code by tricking users into opening malicious pr...
Dec 9, 2020A heap overflow vulnerability in Pixar OpenUSD 20.05 allows remote code execution when parsing specially crafted binary USD files. Attackers can explo...
Nov 13, 2020A heap overflow vulnerability in Pixar OpenUSD 20.05 allows attackers to execute arbitrary code or cause denial of service by parsing specially crafte...
Nov 13, 2020A heap overflow vulnerability in Pixar OpenUSD 20.05 allows attackers to execute arbitrary code or cause denial of service by tricking users into open...
Nov 13, 2020A heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC's submitForm function allows arbitrary code execution when a user opens a malici...
Nov 5, 2020ImageMagick versions before 7.1.2-1 contain a heap-buffer overflow vulnerability in the MNG image format parser that can leak memory contents into out...
Aug 13, 2025This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based...
Oct 17, 2024This vulnerability in Zephyr RTOS's Bluetooth Host Controller Interface (HCI) allows improper discarding of advertising extension reports, potentially...
Sep 13, 2024This CVE describes a heap-based buffer overflow vulnerability in Zephyr RTOS Bluetooth Classic stack due to missing buffer length checks. Attackers ca...
Sep 13, 2024A heap-based buffer overflow vulnerability in free5GC go-upf versions before 1.2.8 allows remote attackers to cause denial of service by sending speci...
Feb 23, 2026A heap buffer overflow vulnerability in free5GC's UPF component allows remote attackers to crash the UPF service via specially crafted PFCP Session Mo...
Feb 13, 2026A heap buffer overflow vulnerability in Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) by sending a specially...
Feb 12, 2026A heap buffer overflow vulnerability in Fast DDS allows remote attackers to terminate the Fast-DDS process by sending specially crafted SPDP packets w...
Feb 3, 2026This vulnerability in Fast DDS allows remote attackers to cause denial-of-service by sending specially crafted SPDP packets with manipulated DATA Subm...
Feb 3, 2026FreeRDP clients prior to version 3.21.0 contain a buffer overflow vulnerability in FastGlyph parsing. A malicious RDP server can exploit this to cause...
Jan 19, 2026A buffer overflow vulnerability in the gnu_special function of BinUtils' cplus-dem.c file allows attackers to crash applications by processing special...
Dec 29, 2025A buffer overflow vulnerability in the strcat function within libming 0.4.8 allows attackers to execute arbitrary code or cause denial of service. Thi...
Dec 29, 2025An integer underflow vulnerability in AIS-catcher's MQTT parsing allows attackers to trigger heap buffer overflow via malformed packets. This can caus...
Nov 29, 2025A heap overflow vulnerability in Suricata's logging functionality can cause crashes when specific alert queue conditions are met. This affects Suricat...
Nov 26, 2025This vulnerability allows remote attackers to execute arbitrary code on affected devices by exploiting an out-of-bounds write in the modem firmware wh...
Nov 4, 2025A heap-based buffer overflow vulnerability in Fortinet's FortiOS, FortiPAM, and FortiProxy allows authenticated users to execute arbitrary code via cr...
Oct 14, 2025A buffer overflow vulnerability in D-Link DI-7100G routers allows attackers to execute arbitrary code or cause denial of service by exploiting the via...
Sep 23, 2025A heap buffer overflow vulnerability in tcpliveplay utility of tcpreplay 4.5.1 allows attackers to cause denial of service by processing a malicious p...
Sep 23, 2025CVE-2025-40930 is an integer buffer overflow vulnerability in JSON::SIMD Perl module versions before 1.07. When parsing malicious JSON input, it cause...
Sep 8, 2025A heap-based buffer overflow vulnerability in Ivanti secure access products allows remote unauthenticated attackers to trigger denial of service. This...
Aug 12, 2025A buffer overflow vulnerability in IBM Semeru Runtime's native AES/CBC encryption implementation allows attackers to cause denial of service through a...
May 14, 2025About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 855 CVEs classified as CWE-122, with 108 rated critical and 668 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free