CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

860
Total CVEs
109
Critical
672
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 86
3 Google 32
4 Fedoraproject 32
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (860)

CVE-2025-22134
4.2

CVE-2025-22134 is a heap-buffer overflow vulnerability in Vim that occurs when switching buffers using the :all command while visual mode is active. T...

Jan 13, 2025
CVE-2025-63927
4.0

A heap-use-after-free vulnerability in airpig2011 IEC104 software allows attackers to cause program crashes or memory corruption by exploiting imprope...

Nov 12, 2025
CVE-2025-68469
3.3

ImageMagick versions before 7.1.1-14 contain a heap-based buffer overflow vulnerability (CWE-122) when processing specially crafted TIFF files. This c...

Dec 18, 2025
CVE-2025-64524
3.3

A heap-buffer-overflow vulnerability in the rastertopclx filter of cups-filters allows memory corruption when processing malicious input. This can cau...

Nov 20, 2025
CVE-2025-46643
2.3

A heap-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows high-privileged attackers with local access to cause den...

Jan 9, 2026
CVE-2025-11961
1.9

CVE-2025-11961 is a heap-based buffer overflow vulnerability in libpcap's pcap_ether_aton() function. When applications pass malformed MAC address str...

Dec 31, 2025
CVE-2026-24679
N/A

This vulnerability in FreeRDP allows remote attackers to cause an out-of-bounds read by providing malicious interface numbers to the URBDRC client. Th...

Feb 9, 2026
CVE-2026-24682
N/A

This CVE describes a heap-based out-of-bounds access vulnerability in FreeRDP's audio handling component. When parsing audio formats fails, the code i...

Feb 9, 2026
CVE-2025-65079
N/A

A heap-based buffer overflow vulnerability in the Postscript interpreter of Lexmark devices allows attackers to execute arbitrary code as an unprivile...

Feb 3, 2026
CVE-2026-24822
N/A

This CVE describes a heap-based buffer overflow vulnerability in the wxhelper software's mongoose.C module, allowing attackers to write data beyond al...

Jan 27, 2026

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 860 CVEs classified as CWE-122, with 109 rated critical and 672 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free