CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (857)
A buffer overflow vulnerability in IBM Semeru Runtime's native AES/CBC encryption implementation allows attackers to cause denial of service through a...
May 14, 2025CVE-2025-3712 is a heap-based buffer overflow vulnerability in LCD KVM over IP Switch CL5708IM firmware that allows unauthenticated remote attackers t...
May 9, 2025A heap-based buffer overflow vulnerability in RT-Labs P-Net library allows attackers to crash industrial control system IO devices by sending maliciou...
May 7, 2025A heap-based buffer overflow vulnerability in RT-Labs P-Net library allows attackers to crash industrial control system devices by sending malicious R...
May 7, 2025A heap-based buffer overflow vulnerability in Juniper Networks Junos OS flexible PIC concentrator (FPC) allows attackers to send specific DHCP packets...
Apr 9, 2025A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows remote unauthenticated attackers to execute arbi...
Apr 8, 2025A heap buffer overflow vulnerability exists in the smooth2() function of lcms2-2.16's cmsgamma.c file. This could allow remote attackers to cause deni...
Apr 1, 2025This vulnerability is a heap-based buffer overflow in Windows Core Messaging that allows an authenticated attacker to execute arbitrary code with elev...
Mar 11, 2025A heap overflow vulnerability in OpenH264 video codec library allows remote attackers to crash applications or potentially execute arbitrary code by t...
Feb 20, 2025This .NET vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects s...
Jan 14, 2025This CVE describes a heap-based buffer overflow vulnerability in .NET and Visual Studio that could allow remote code execution. Attackers could exploi...
Jan 14, 2025This vulnerability allows attackers to cause a heap-based buffer overflow in Zephyr RTOS Bluetooth Object Transfer Service (OTS) client by sending mal...
Dec 16, 2024A heap-based buffer overflow vulnerability in Juniper Networks Junos OS telemetry sensor process (sensord) causes memory leaks when specific telemetry...
Jul 10, 2024CVE-2024-35434 is a heap buffer overflow vulnerability in Irontec Sngrep v1.8.1's RTP packet processing function. Attackers can exploit this by sendin...
May 29, 2024This heap overflow vulnerability in libvpx allows attackers to execute arbitrary code or cause denial of service by encoding VP9 video frames with dim...
May 27, 2024This vulnerability in xmllint (part of libxml2) allows attackers to trigger a buffer over-read when formatting error messages with the --htmlout flag....
May 14, 2024IBM MQ Appliance 9.3 CD and LTS have a heap-based buffer overflow vulnerability due to improper bounds checking. Remote authenticated attackers can ex...
Apr 27, 2024CVE-2024-28896 is a Secure Boot security feature bypass vulnerability that allows an attacker with physical access or administrative privileges to byp...
Apr 9, 2024A heap-based buffer overflow in the logger_generic function of the Ax_rtu binary allows remote authenticated attackers to cause memory corruption, pot...
Mar 5, 2024This vulnerability in Microsoft ODBC Driver allows remote attackers to execute arbitrary code on affected systems by sending specially crafted request...
Feb 13, 2024An out-of-bounds write vulnerability in grub2's NTFS filesystem driver allows attackers to corrupt heap metadata by presenting a specially crafted NTF...
Oct 25, 2023CVE-2023-5344 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 9.0.1969. Attackers can exploit this by tricking user...
Oct 2, 2023This vulnerability allows remote attackers to execute arbitrary code on Windows systems via specially crafted Bluetooth packets. Attackers can exploit...
Apr 11, 2023This vulnerability allows remote code execution on systems using Microsoft's Protected Extensible Authentication Protocol (PEAP) for network authentic...
Feb 14, 2023This vulnerability in NHI's health insurance web service allows remote attackers to cause a heap-based buffer overflow by sending overly long input st...
Jun 20, 2022A heap-based buffer overflow vulnerability in multiple Mitsubishi Electric industrial automation software products allows remote unauthenticated attac...
Feb 19, 2021A heap overflow vulnerability in FactoryTalk Linx versions 6.11 and earlier allows remote unauthenticated attackers to send malicious set attribute re...
Nov 26, 2020A heap buffer overflow vulnerability in QEMU's virtio-snd device allows attackers to write beyond allocated memory boundaries when processing audio in...
Nov 14, 2024CVE-2024-32619 is a heap-based buffer overflow vulnerability in the HDF5 library's H5T_copy_reopen function that can corrupt the instruction pointer, ...
May 14, 2024CVE-2024-32613 is a heap-based buffer over-read vulnerability in the HDF5 library's H5HL__fl_deserialize function. This allows attackers to read memor...
May 14, 2024This CVE describes a heap buffer overflow vulnerability in HDF5 library versions through 1.14.3. Attackers can exploit this to corrupt the instruction...
May 14, 2024This vulnerability in Redis allows authenticated users to trigger a heap overflow by executing specially crafted COMMAND GETKEYS or COMMAND GETKEYSAND...
Jul 11, 2023This vulnerability allows an attacker with local access to exploit a heap-based buffer overflow in Windows Bluetooth drivers to execute arbitrary code...
May 9, 2023This vulnerability in the Quram Agif library allows attackers to execute arbitrary code due to improper boundary checking. It affects Samsung mobile d...
Apr 11, 2022A heap-based buffer overflow vulnerability in Windows Hyper-V allows authenticated attackers to execute arbitrary code on the host system. This affect...
Feb 10, 2026A heap-based buffer overflow vulnerability in the image module allows attackers to crash affected systems, potentially causing denial of service. This...
Feb 6, 2026A heap-based buffer overflow vulnerability in Azure Monitor Agent allows unauthorized local attackers to execute arbitrary code on affected systems. T...
Nov 11, 2025This vulnerability in GIMP allows attackers to trigger heap buffer overflows by tricking users into opening specially crafted TGA image files. The fla...
May 27, 2025A heap-based buffer overflow vulnerability in giflib's gif2rgb utility allows attackers to execute arbitrary code or cause denial of service by proces...
Apr 14, 2025A heap buffer overflow vulnerability exists in lcms2-2.16's UnrollChunkyBytes function in cmspack.c, which handles color space transformations. This c...
Apr 1, 2025This critical vulnerability in MicroPython 1.23.0 allows remote attackers to execute arbitrary code or cause denial of service via a heap-based buffer...
Sep 17, 2024A critical heap-based buffer overflow vulnerability exists in c-blosc2's ndlz8_decompress function, allowing remote attackers to execute arbitrary cod...
Apr 2, 2024CVE-2024-2212 is a heap buffer overflow vulnerability in Eclipse ThreadX's FreeRTOS compatibility layer. Missing parameter checks in xQueueCreate() an...
Mar 26, 2024CVE-2024-20696 is a heap-based buffer overflow vulnerability in Windows libarchive that allows remote attackers to execute arbitrary code by tricking ...
Jan 9, 2024A heap buffer overflow vulnerability in Samsung Notes' libSPenBase library allows attackers to execute arbitrary code on affected devices. This affect...
Oct 6, 2021This vulnerability in Microsoft Windows Performance Data Helper Library allows remote attackers to execute arbitrary code on affected systems by sendi...
Jul 9, 2024A heap-based buffer overflow vulnerability in Realtek rtl819x Jungle SDK allows arbitrary code execution when processing malicious .dat configuration ...
Jul 8, 2024A heap-based buffer overflow vulnerability in Dell PowerEdge Server BIOS allows local high-privileged attackers to write to unauthorized memory. This ...
Mar 19, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows Active Directory Certificate Services (AD CS) servers by sending speci...
Jul 11, 2023A heap-based buffer overflow vulnerability in Intel SoC Watch software allows privileged users to potentially escalate privileges via local access. Th...
May 12, 2023About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 857 CVEs classified as CWE-122, with 108 rated critical and 670 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free