CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

860
Total CVEs
109
Critical
672
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 86
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (860)

CVE-2024-22453
7.2

A heap-based buffer overflow vulnerability in Dell PowerEdge Server BIOS allows local high-privileged attackers to write to unauthorized memory. This ...

Mar 19, 2024
CVE-2023-35350
7.2

This vulnerability allows remote attackers to execute arbitrary code on Windows Active Directory Certificate Services (AD CS) servers by sending speci...

Jul 11, 2023
CVE-2023-30763
7.2

A heap-based buffer overflow vulnerability in Intel SoC Watch software allows privileged users to potentially escalate privileges via local access. Th...

May 12, 2023
CVE-2023-28254
7.2

CVE-2023-28254 is a heap-based buffer overflow vulnerability in Windows DNS Server that allows remote attackers to execute arbitrary code with SYSTEM ...

Apr 11, 2023
CVE-2025-64784
7.1

CVE-2025-64784 is a heap-based buffer overflow vulnerability in DNG SDK versions 1.7.0 and earlier, allowing attackers to disclose sensitive memory in...

Dec 9, 2025
CVE-2025-65018
7.1

A heap buffer overflow vulnerability in libpng's simplified API allows attackers to execute arbitrary code or cause denial of service by crafting mali...

Nov 25, 2025
CVE-2025-11206
7.1

A heap buffer overflow vulnerability in Chrome's video processing component allows remote attackers to execute arbitrary code via a malicious HTML pag...

Nov 6, 2025
CVE-2025-57107
7.1

A heap buffer overflow vulnerability in Kitware VTK's GLTF file parser allows attackers to execute arbitrary code or cause denial of service by provid...

Oct 31, 2025
CVE-2025-48379
7.1

This CVE describes a heap buffer overflow vulnerability in the Python Pillow library when saving large DDS format images. Attackers could potentially ...

Jul 1, 2025
CVE-2025-1252
7.1

A heap-based buffer overflow vulnerability in RTI Connext Professional Core Libraries allows attackers to overflow variables and tags, potentially lea...

May 8, 2025
CVE-2024-38170
7.1

This vulnerability allows remote code execution when a user opens a specially crafted Excel file. Attackers could exploit this to run arbitrary code w...

Aug 13, 2024
CVE-2023-21406
7.1

A heap-based buffer overflow vulnerability in AXIS A1001's OSDP communication handler allows attackers to write data beyond allocated memory boundarie...

Jul 25, 2023
CVE-2022-34400
7.1

This CVE describes a heap buffer overflow vulnerability in Dell BIOS that allows a local attacker with administrative privileges to perform arbitrary ...

Feb 1, 2023
CVE-2022-1437
7.1

CVE-2022-1437 is a heap-based buffer overflow vulnerability in radare2 reverse engineering framework versions prior to 5.7.0. This allows attackers to...

Apr 22, 2022
CVE-2022-0713
7.1

CVE-2022-0713 is a heap-based buffer overflow vulnerability in radare2 reverse engineering framework versions prior to 5.6.4. Attackers can exploit th...

Feb 22, 2022
CVE-2020-27752
7.1

CVE-2020-27752 is a heap buffer overflow vulnerability in ImageMagick's quantum-private.h component. Attackers can exploit this by submitting crafted ...

Dec 8, 2020
CVE-2025-67896
7.0

A heap-based buffer overflow vulnerability in Exim mail servers with certain non-default rate-limit configurations allows remote attackers to potentia...

Dec 14, 2025
CVE-2025-49744
7.0

A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows authenticated attackers to execute arbitrary code with elevated priv...

Jul 8, 2025
CVE-2025-49727
7.0

CVE-2025-49727 is a heap-based buffer overflow vulnerability in the Windows Win32K graphics subsystem that allows an authenticated attacker to execute...

Jul 8, 2025
CVE-2025-21414
7.0

This is a Windows Core Messaging elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on affected ...

Feb 11, 2025
CVE-2025-21184
7.0

This vulnerability in Windows Core Messaging allows attackers to escalate privileges on affected systems. It affects Windows operating systems and req...

Feb 11, 2025
CVE-2024-51737
7.0

This CVE describes an integer overflow vulnerability in RediSearch, a Redis module for querying and full-text search. Authenticated Redis users can tr...

Jan 8, 2025
CVE-2024-51480
7.0

This vulnerability in RedisTimeSeries allows authenticated users to trigger an integer overflow and heap overflow by sending specially crafted argumen...

Jan 8, 2025
CVE-2024-0156
7.0

A buffer overflow vulnerability in Dell Digital Delivery allows local low-privileged attackers to execute arbitrary code or escalate privileges. This ...

Mar 4, 2024
CVE-2022-36764
7.0

CVE-2022-36764 is a heap buffer overflow vulnerability in EDK2's Tcg2MeasurePeImage() function that allows local network attackers to potentially exec...

Jan 9, 2024
CVE-2023-47118
7.0

A heap buffer overflow vulnerability exists in ClickHouse's T64 codec decompression logic. Unauthenticated attackers can send specially crafted payloa...

Dec 20, 2023
CVE-2023-47038
7.0

This vulnerability in Perl allows an attacker to trigger a heap buffer overflow by providing a malicious regular expression. Systems running affected ...

Dec 18, 2023
CVE-2022-24834
7.0

CVE-2022-24834 is a heap overflow vulnerability in Redis's cjson library that can be triggered via specially crafted Lua scripts. This can lead to hea...

Jul 13, 2023
CVE-2023-33152
7.0

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow in Microsoft Activ...

Jul 11, 2023
CVE-2023-28218
7.0

This vulnerability in the Windows Ancillary Function Driver for WinSock allows attackers to escalate privileges from a low-privileged user account to ...

Apr 11, 2023
CVE-2020-13600
7.0

A heap-based buffer overflow vulnerability in Zephyr RTOS's eswifi SPI driver allows attackers to corrupt kernel memory by sending malformed SPI respo...

May 25, 2021
CVE-2026-24922
6.9

A buffer overflow vulnerability in the HDC module allows attackers to crash affected systems, potentially causing denial of service. This affects Huaw...

Feb 6, 2026
CVE-2025-63701
6.8

A heap corruption vulnerability in the Advantech TP-3250 printer driver allows attackers with local access to cause application crashes or potentially...

Nov 14, 2025
CVE-2025-5517
6.8

A heap-based buffer overflow vulnerability in ABB Terra AC wallbox charging stations allows attackers to execute arbitrary code or cause denial of ser...

Oct 20, 2025
CVE-2025-54630
6.8

This vulnerability in the DFA module allows attackers to cause denial of service by exploiting insufficient data length verification. It affects Huawe...

Aug 6, 2025
CVE-2024-0145
6.8

This vulnerability in NVIDIA's nvJPEG2000 library allows attackers to execute arbitrary code or tamper with data by sending specially crafted JPEG2000...

Feb 12, 2025
CVE-2024-20517
6.8

This vulnerability allows authenticated administrators on Cisco Small Business routers to send crafted HTTP requests that cause the device to unexpect...

Oct 2, 2024
CVE-2024-38161
6.8

This vulnerability in the Windows Mobile Broadband Driver allows attackers to execute arbitrary code remotely on affected systems. It affects Windows ...

Aug 13, 2024
CVE-2026-20876
6.7

A heap-based buffer overflow vulnerability in Windows Virtualization-Based Security (VBS) Enclave allows authenticated attackers to execute arbitrary ...

Jan 13, 2026
CVE-2025-20741
6.7

This CVE describes an out-of-bounds write vulnerability in MediaTek wlan AP drivers that could allow local privilege escalation. Attackers with initia...

Nov 4, 2025
CVE-2024-6154
6.7

This is a heap-based buffer overflow vulnerability in Parallels Desktop's Toolgate component that allows local attackers to escalate privileges. Attac...

Jun 20, 2024
CVE-2026-25749
6.6

A heap buffer overflow vulnerability in Vim's tag file resolution logic allows attackers to execute arbitrary code or crash the application by exploit...

Feb 6, 2026
CVE-2026-21504
6.6

CVE-2026-21504 is a heap buffer overflow vulnerability in the ToneMap parser of iccDEV color management libraries. This allows attackers to execute ar...

Jan 7, 2026
CVE-2024-49081
6.6

This vulnerability in Windows Wireless Wide Area Network Service (WwanSvc) allows attackers to escalate privileges from a lower-privileged account to ...

Dec 12, 2024
CVE-2026-26284
6.5

ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain an out-of-bounds read vulnerability when processing Huffman-coded data in PCD files due to ...

Feb 24, 2026
CVE-2026-25897
6.5

An integer overflow vulnerability in ImageMagick's SUN decoder allows attackers to trigger an out-of-bounds heap write on 32-bit systems. This can pot...

Feb 24, 2026
CVE-2026-23567
6.5

An integer underflow vulnerability in TeamViewer DEX Client's UDP command handler allows adjacent network attackers to trigger heap-based buffer overf...

Jan 29, 2026
CVE-2026-24829
6.5

CVE-2026-24829 is a heap-based buffer overflow vulnerability in Is-Daouda's is-Engine software that allows attackers to write data beyond allocated me...

Jan 27, 2026
CVE-2025-70299
6.5

A heap overflow vulnerability in GPAC's AVI file parser allows attackers to cause denial of service by providing a specially crafted AVI file. This af...

Jan 15, 2026
CVE-2025-65406
6.5

A heap overflow vulnerability in Live555 Streaming Media allows attackers to cause denial of service by supplying a specially crafted MKV file. This a...

Dec 1, 2025

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 860 CVEs classified as CWE-122, with 109 rated critical and 672 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free