CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

860
Total CVEs
109
Critical
672
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 86
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (860)

CVE-2025-51089
6.5

A heap-based buffer overflow vulnerability exists in Tenda AC8V4 routers via the /goform/GetParentControlInfo endpoint when manipulating the 'mac' arg...

Jul 24, 2025
CVE-2025-32990
6.5

This CVE describes a heap-buffer-overflow vulnerability in GnuTLS's certtool utility when parsing template files. An attacker can trigger memory corru...

Jul 10, 2025
CVE-2025-53180
6.5

A null pointer dereference vulnerability in the PDF preview module could cause application crashes or instability when processing malicious PDF files....

Jul 7, 2025
CVE-2025-53182
6.5

A null pointer dereference vulnerability in the PDF preview module could cause application crashes or denial of service. This affects systems using Hu...

Jul 7, 2025
CVE-2025-53184
6.5

A null pointer dereference vulnerability in the PDF preview module could cause application crashes or denial of service. This affects systems running ...

Jul 7, 2025
CVE-2025-45029
6.5

This vulnerability allows attackers to execute arbitrary code or cause denial of service on WINSTAR WN572HP3 devices by exploiting a heap overflow in ...

Jul 2, 2025
CVE-2024-42437
6.5

A buffer overflow vulnerability in Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers allows authenticated users to cause denial of servi...

Aug 14, 2024
CVE-2024-38950
6.5

CVE-2024-38950 is a heap buffer overflow vulnerability in Libde265 v1.0.15 that allows attackers to crash applications via crafted payloads to the __i...

Jun 26, 2024
CVE-2024-3758
6.5

This vulnerability allows a local attacker to execute arbitrary code with Trusted Computing Base (TCB) privileges through a heap buffer overflow in Op...

May 7, 2024
CVE-2023-28798
6.5

This vulnerability allows an attacker to write data beyond allocated heap memory boundaries in the pacparser library used by Zscaler Client Connector ...

May 2, 2024
CVE-2024-7272
6.3

A critical heap-based buffer overflow vulnerability in FFmpeg's fill_audiodata function allows remote attackers to execute arbitrary code or cause den...

Aug 12, 2024
CVE-2024-7055
6.3

A critical heap-based buffer overflow vulnerability exists in FFmpeg's PNM image decoder (pnm_decode_frame function). Attackers can exploit this remot...

Aug 6, 2024
CVE-2024-41438
6.2

A heap buffer overflow vulnerability in the cp_stored() function of hicolor v0.5.0 allows attackers to cause Denial of Service (DoS) by providing a sp...

Jul 30, 2024
CVE-2024-41440
6.2

A heap buffer overflow vulnerability in the png_quantize() function of hicolor v0.5.0 allows attackers to cause Denial of Service (DoS) by providing a...

Jul 30, 2024
CVE-2026-24852
6.1

A heap buffer over-read vulnerability in iccDEV library versions before 2.3.1.2 allows attackers to potentially leak heap memory contents and cause ap...

Jan 28, 2026
CVE-2026-21494
6.1

A heap buffer overflow vulnerability in iccDEV library's CIccTagLut8::Validate() function allows attackers to execute arbitrary code or cause denial o...

Jan 6, 2026
CVE-2026-21490
6.1

A heap buffer overflow vulnerability in iccDEV library's CIccTagLut16::Validate() function allows attackers to execute arbitrary code or cause denial ...

Jan 6, 2026
CVE-2026-21491
6.1

A buffer overflow vulnerability in iccDEV's CIccTagTextDescription function allows attackers to execute arbitrary code or crash applications by proces...

Jan 6, 2026
CVE-2024-55627
5.9

This vulnerability in Suricata allows an attacker to trigger a large buffer overflow via specially crafted TCP streams, potentially leading to denial ...

Jan 6, 2025
CVE-2024-38796
5.9

This vulnerability in EDK2's PeCoffLoaderRelocateImage() function allows memory corruption via a heap-based buffer overflow when processing specially ...

Sep 27, 2024
CVE-2024-20508
5.8

An unauthenticated remote attacker can bypass security policies or cause denial of service on Cisco IOS XE devices with UTD Snort IPS Engine by sendin...

Sep 25, 2024
CVE-2025-40929
5.6

CVE-2025-40929 is an integer buffer overflow vulnerability in Cpanel::JSON::XS Perl module versions before 4.40. When parsing malicious JSON input, it...

Sep 8, 2025
CVE-2024-56826
5.6

A heap buffer overflow vulnerability exists in OpenJPEG's opj_decompress utility when specific options are used. This can cause application crashes or...

Jan 9, 2025
CVE-2025-70302
5.5

A heap overflow vulnerability in GPAC's ghi_dmx_declare_opid_bin() function allows attackers to cause Denial of Service (DoS) through specially crafte...

Jan 15, 2026
CVE-2025-70303
5.5

A heap overflow vulnerability in GPAC's uncv_parse_config() function allows attackers to cause Denial of Service (DoS) by providing a specially crafte...

Jan 15, 2026
CVE-2025-70310
5.5

A heap overflow vulnerability in GPAC's vorbis_to_intern() function allows attackers to cause Denial of Service (DoS) by processing a malicious .ogg f...

Jan 15, 2026
CVE-2025-50054
5.5

A buffer overflow vulnerability in OpenVPN's ovpn-dco-win kernel driver allows local user processes to send oversized control messages, causing system...

Jun 20, 2025
CVE-2025-31177
5.5

CVE-2025-31177 is a heap buffer overflow vulnerability in gnuplot's utf8_copy_one function that could allow attackers to execute arbitrary code or cau...

May 7, 2025
CVE-2025-29769
5.5

A heap buffer overflow vulnerability in libvips' heifsave operation when processing specially crafted TIFF images with 4 channels. This could cause ap...

Apr 7, 2025
CVE-2024-53310
5.5

A buffer overflow vulnerability in Effectmatrix Total Video Converter Command Line (TVCC) version 2.50 allows attackers to execute arbitrary code or c...

Feb 13, 2025
CVE-2024-30066
5.5

CVE-2024-30066 is a Winlogon elevation of privilege vulnerability in Windows that allows authenticated attackers to gain SYSTEM privileges. This affec...

Jun 11, 2024
CVE-2025-49604
5.4

A heap-based buffer overflow vulnerability in Realtek AmebaD devices' WLAN driver defragment function allows attackers to potentially execute arbitrar...

Jul 9, 2025
CVE-2020-12819
5.4

A heap-based buffer overflow vulnerability in FortiGate's SSL VPN daemon allows remote attackers with valid SSL VPN credentials to crash the service b...

Dec 19, 2024
CVE-2026-26967
5.3

A critical heap-based buffer overflow vulnerability in PJSIP's H.264 unpacketizer allows remote attackers to execute arbitrary code or cause denial of...

Feb 20, 2026
CVE-2025-20734
5.3

This vulnerability in MediaTek wlan AP driver allows local privilege escalation through an out-of-bounds write due to incorrect bounds checking. An at...

Nov 4, 2025
CVE-2025-20731
5.3

This vulnerability in MediaTek wlan AP driver allows local privilege escalation via an out-of-bounds write when a malicious actor already has System p...

Nov 4, 2025
CVE-2025-43912
5.3

A heap-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows unauthenticated remote attackers to cause denial of serv...

Oct 7, 2025
CVE-2024-48075
5.3

A heap buffer overflow vulnerability in SharkSSL's TLS server-side handshake implementation allows remote attackers to cause denial-of-service by send...

Nov 12, 2024
CVE-2024-6383
5.3

A heap buffer overflow vulnerability in MongoDB C Driver's bson_string_append function could allow memory corruption when processing BSON strings. Thi...

Jul 3, 2024
CVE-2026-25576
5.1

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a heap buffer over-read vulnerability when processing raw image formats. Attackers can tr...

Feb 24, 2026
CVE-2025-0662
4.9

CVE-2025-0662 is a kernel memory leak vulnerability in FreeBSD's ktrace facility that allows unprivileged userspace programs to read up to 14 bytes of...

Jan 30, 2025
CVE-2025-67873
4.8

Capstone disassembly framework versions 6.0.0-Alpha5 and prior contain a heap buffer overflow vulnerability in the disassembly path. An attacker can t...

Dec 17, 2025
CVE-2024-43168
4.8

This CVE describes a heap-buffer-overflow vulnerability in Unbound's cfg_mark_ports function that could allow memory corruption. According to the orig...

Aug 12, 2024
CVE-2024-10253
4.7

A Time-of-Check Time-of-Use (TOCTOU) vulnerability in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker to cause a ...

Jan 14, 2025
CVE-2024-37601
4.6

A heap buffer overflow vulnerability exists in the user data import/export function of Mercedes Benz NTG 6 head units. Attackers with physical access ...

Feb 13, 2025
CVE-2025-47814
4.5

CVE-2025-47814 is a heap-based buffer overflow vulnerability in GNU PSPP's libpspp-core.a library that occurs when processing specially crafted ZIP fi...

May 10, 2025
CVE-2024-45306
4.5

A heap buffer overflow vulnerability in Vim text editor occurs when cursor position becomes invalid and points beyond line boundaries, potentially cau...

Sep 2, 2024
CVE-2023-20029
4.4

This vulnerability in Cisco IOS XE Software allows authenticated local attackers to gain root privileges by exploiting insufficient memory protection ...

Mar 23, 2023
CVE-2025-20729
4.2

This CVE describes an out-of-bounds write vulnerability in MediaTek wlan AP drivers due to incorrect bounds checking. It allows local privilege escala...

Nov 4, 2025
CVE-2025-24477
4.2

A heap-based buffer overflow vulnerability in Fortinet FortiOS allows authenticated attackers to escalate privileges via specially crafted CLI command...

Jul 15, 2025

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 860 CVEs classified as CWE-122, with 109 rated critical and 672 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free