CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

857
Total CVEs
108
Critical
670
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 86
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (857)

CVE-2025-2900
7.5

A buffer overflow vulnerability in IBM Semeru Runtime's native AES/CBC encryption implementation allows attackers to cause denial of service through a...

May 14, 2025
CVE-2025-3712
7.5

CVE-2025-3712 is a heap-based buffer overflow vulnerability in LCD KVM over IP Switch CL5708IM firmware that allows unauthenticated remote attackers t...

May 9, 2025
CVE-2025-32396
7.5

A heap-based buffer overflow vulnerability in RT-Labs P-Net library allows attackers to crash industrial control system IO devices by sending maliciou...

May 7, 2025
CVE-2025-32400
7.5

A heap-based buffer overflow vulnerability in RT-Labs P-Net library allows attackers to crash industrial control system devices by sending malicious R...

May 7, 2025
CVE-2025-30644
7.5

A heap-based buffer overflow vulnerability in Juniper Networks Junos OS flexible PIC concentrator (FPC) allows attackers to send specific DHCP packets...

Apr 9, 2025
CVE-2025-26668
7.5

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows remote unauthenticated attackers to execute arbi...

Apr 8, 2025
CVE-2025-29070
7.5

A heap buffer overflow vulnerability exists in the smooth2() function of lcms2-2.16's cmsgamma.c file. This could allow remote attackers to cause deni...

Apr 1, 2025
CVE-2025-26634
7.5

This vulnerability is a heap-based buffer overflow in Windows Core Messaging that allows an authenticated attacker to execute arbitrary code with elev...

Mar 11, 2025
CVE-2025-27091
7.5

A heap overflow vulnerability in OpenH264 video codec library allows remote attackers to crash applications or potentially execute arbitrary code by t...

Feb 20, 2025
CVE-2025-21171
7.5

This .NET vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects s...

Jan 14, 2025
CVE-2025-21172
7.5

This CVE describes a heap-based buffer overflow vulnerability in .NET and Visual Studio that could allow remote code execution. Attackers could exploi...

Jan 14, 2025
CVE-2024-8798
7.5

This vulnerability allows attackers to cause a heap-based buffer overflow in Zephyr RTOS Bluetooth Object Transfer Service (OTS) client by sending mal...

Dec 16, 2024
CVE-2024-39518
7.5

A heap-based buffer overflow vulnerability in Juniper Networks Junos OS telemetry sensor process (sensord) causes memory leaks when specific telemetry...

Jul 10, 2024
CVE-2024-35434
7.5

CVE-2024-35434 is a heap buffer overflow vulnerability in Irontec Sngrep v1.8.1's RTP packet processing function. Attackers can exploit this by sendin...

May 29, 2024
CVE-2023-6349
7.5

This heap overflow vulnerability in libvpx allows attackers to execute arbitrary code or cause denial of service by encoding VP9 video frames with dim...

May 27, 2024
CVE-2024-34459
7.5

This vulnerability in xmllint (part of libxml2) allows attackers to trigger a buffer over-read when formatting error messages with the --htmlout flag....

May 14, 2024
CVE-2024-25048
7.5

IBM MQ Appliance 9.3 CD and LTS have a heap-based buffer overflow vulnerability due to improper bounds checking. Remote authenticated attackers can ex...

Apr 27, 2024
CVE-2024-28896
7.5

CVE-2024-28896 is a Secure Boot security feature bypass vulnerability that allows an attacker with physical access or administrative privileges to byp...

Apr 9, 2024
CVE-2023-45591
7.5

A heap-based buffer overflow in the logger_generic function of the Ax_rtu binary allows remote authenticated attackers to cause memory corruption, pot...

Mar 5, 2024
CVE-2024-21347
7.5

This vulnerability in Microsoft ODBC Driver allows remote attackers to execute arbitrary code on affected systems by sending specially crafted request...

Feb 13, 2024
CVE-2023-4692
7.5

An out-of-bounds write vulnerability in grub2's NTFS filesystem driver allows attackers to corrupt heap metadata by presenting a specially crafted NTF...

Oct 25, 2023
CVE-2023-5344
7.5

CVE-2023-5344 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.1969. Attackers can exploit this by tricking user...

Oct 2, 2023
CVE-2023-28227
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems via specially crafted Bluetooth packets. Attackers can exploit...

Apr 11, 2023
CVE-2023-21695
7.5

This vulnerability allows remote code execution on systems using Microsoft's Protected Extensible Authentication Protocol (PEAP) for network authentic...

Feb 14, 2023
CVE-2021-45918
7.5

This vulnerability in NHI's health insurance web service allows remote attackers to cause a heap-based buffer overflow by sending overly long input st...

Jun 20, 2022
CVE-2021-20587
7.5

A heap-based buffer overflow vulnerability in multiple Mitsubishi Electric industrial automation software products allows remote unauthenticated attac...

Feb 19, 2021
CVE-2020-27255
7.5

A heap overflow vulnerability in FactoryTalk Linx versions 6.11 and earlier allows remote unauthenticated attackers to send malicious set attribute re...

Nov 26, 2020
CVE-2024-7730
7.4

A heap buffer overflow vulnerability in QEMU's virtio-snd device allows attackers to write beyond allocated memory boundaries when processing audio in...

Nov 14, 2024
CVE-2024-32619
7.4

CVE-2024-32619 is a heap-based buffer overflow vulnerability in the HDF5 library's H5T_copy_reopen function that can corrupt the instruction pointer, ...

May 14, 2024
CVE-2024-32613
7.4

CVE-2024-32613 is a heap-based buffer over-read vulnerability in the HDF5 library's H5HL__fl_deserialize function. This allows attackers to read memor...

May 14, 2024
CVE-2024-29163
7.4

This CVE describes a heap buffer overflow vulnerability in HDF5 library versions through 1.14.3. Attackers can exploit this to corrupt the instruction...

May 14, 2024
CVE-2023-36824
7.4

This vulnerability in Redis allows authenticated users to trigger a heap overflow by executing specially crafted COMMAND GETKEYS or COMMAND GETKEYSAND...

Jul 11, 2023
CVE-2023-24948
7.4

This vulnerability allows an attacker with local access to exploit a heap-based buffer overflow in Windows Bluetooth drivers to execute arbitrary code...

May 9, 2023
CVE-2022-26092
7.4

This vulnerability in the Quram Agif library allows attackers to execute arbitrary code due to improper boundary checking. It affects Samsung mobile d...

Apr 11, 2022
CVE-2026-21248
7.3

A heap-based buffer overflow vulnerability in Windows Hyper-V allows authenticated attackers to execute arbitrary code on the host system. This affect...

Feb 10, 2026
CVE-2026-24925
7.3

A heap-based buffer overflow vulnerability in the image module allows attackers to crash affected systems, potentially causing denial of service. This...

Feb 6, 2026
CVE-2025-59504
7.3

A heap-based buffer overflow vulnerability in Azure Monitor Agent allows unauthorized local attackers to execute arbitrary code on affected systems. T...

Nov 11, 2025
CVE-2025-48797
7.3

This vulnerability in GIMP allows attackers to trigger heap buffer overflows by tricking users into opening specially crafted TGA image files. The fla...

May 27, 2025
CVE-2025-31344
7.3

A heap-based buffer overflow vulnerability in giflib's gif2rgb utility allows attackers to execute arbitrary code or cause denial of service by proces...

Apr 14, 2025
CVE-2025-29069
7.3

A heap buffer overflow vulnerability exists in lcms2-2.16's UnrollChunkyBytes function in cmspack.c, which handles color space transformations. This c...

Apr 1, 2025
CVE-2024-8948
7.3

This critical vulnerability in MicroPython 1.23.0 allows remote attackers to execute arbitrary code or cause denial of service via a heap-based buffer...

Sep 17, 2024
CVE-2024-3203
7.3

A critical heap-based buffer overflow vulnerability exists in c-blosc2's ndlz8_decompress function, allowing remote attackers to execute arbitrary cod...

Apr 2, 2024
CVE-2024-2212
7.3

CVE-2024-2212 is a heap buffer overflow vulnerability in Eclipse ThreadX's FreeRTOS compatibility layer. Missing parameter checks in xQueueCreate() an...

Mar 26, 2024
CVE-2024-20696
7.3

CVE-2024-20696 is a heap-based buffer overflow vulnerability in Windows libarchive that allows remote attackers to execute arbitrary code by tricking ...

Jan 9, 2024
CVE-2021-25495
7.3

A heap buffer overflow vulnerability in Samsung Notes' libSPenBase library allows attackers to execute arbitrary code on affected devices. This affect...

Oct 6, 2021
CVE-2024-38025
7.2

This vulnerability in Microsoft Windows Performance Data Helper Library allows remote attackers to execute arbitrary code on affected systems by sendi...

Jul 9, 2024
CVE-2024-21778
7.2

A heap-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK allows arbitrary code execution when processing malicious .dat configuration ...

Jul 8, 2024
CVE-2024-22453
7.2

A heap-based buffer overflow vulnerability in Dell PowerEdge Server BIOS allows local high-privileged attackers to write to unauthorized memory. This ...

Mar 19, 2024
CVE-2023-35350
7.2

This vulnerability allows remote attackers to execute arbitrary code on Windows Active Directory Certificate Services (AD CS) servers by sending speci...

Jul 11, 2023
CVE-2023-30763
7.2

A heap-based buffer overflow vulnerability in Intel SoC Watch software allows privileged users to potentially escalate privileges via local access. Th...

May 12, 2023

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 857 CVEs classified as CWE-122, with 108 rated critical and 670 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free