CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

834
Total CVEs
106
Critical
649
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 84
3 Google 31
4 Fedoraproject 31
5 Debian 25
6 Vim 23
7 Siemens 15
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (834)

CVE-2024-29157
9.8

CVE-2024-29157 is a critical heap buffer overflow vulnerability in HDF5 library versions through 1.14.3. Attackers can exploit this to corrupt the ins...

May 14, 2024
CVE-2024-34249
9.8

CVE-2024-34249 is a heap buffer overflow vulnerability in wasm3 WebAssembly runtime v0.5.0 that can cause segmentation faults and potentially allow ar...

May 6, 2024
CVE-2023-26793
9.8

CVE-2023-26793 is a critical heap-based buffer overflow vulnerability in libmodbus v3.1.10's read_io_status function that allows remote attackers to e...

May 1, 2024
CVE-2024-32038
9.8

A buffer overflow vulnerability in Wazuh Manager's analysisd component allows remote code execution when processing Unicode characters from Windows Ev...

Apr 19, 2024
CVE-2024-29204
9.8

A heap overflow vulnerability in the WLAvalancheService component of Ivanti Avalanche allows remote unauthenticated attackers to execute arbitrary com...

Apr 19, 2024
CVE-2024-24996
9.8

This is a critical heap overflow vulnerability in Ivanti Avalanche's WLInfoRailService component that allows unauthenticated remote attackers to execu...

Apr 19, 2024
CVE-2024-22857
9.8

CVE-2024-22857 is a critical heap buffer overflow vulnerability in zlog logging library versions 1.1.0 through 1.2.17. An attacker can exploit this to...

Mar 7, 2024
CVE-2024-21795
9.8

A heap-based buffer overflow vulnerability in libbiosig's .egi file parser allows arbitrary code execution when processing malicious files. This affec...

Feb 20, 2024
CVE-2023-29073
9.8

This vulnerability allows attackers to execute arbitrary code or read sensitive data by tricking users into opening malicious MODEL files in AutoCAD. ...

Nov 23, 2023
CVE-2023-4322
9.8

A heap-based buffer overflow vulnerability in radare2 versions prior to 5.9.0 allows attackers to execute arbitrary code or cause denial of service. T...

Aug 14, 2023
CVE-2022-46289
9.8

CVE-2022-46289 is a critical out-of-bounds write vulnerability in Open Babel's ORCA format parser that allows arbitrary code execution when processing...

Jul 21, 2023
CVE-2022-48512
9.8

CVE-2022-48512 is a critical Use After Free vulnerability in Huawei's Vdecoderservice that allows attackers to execute arbitrary code or cause denial ...

Jul 6, 2023
CVE-2023-29363
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Jun 14, 2023
CVE-2023-27997
9.8

A heap-based buffer overflow vulnerability in Fortinet's SSL-VPN implementation allows remote attackers to execute arbitrary code via crafted requests...

Jun 13, 2023
CVE-2023-0851
9.8

A buffer overflow vulnerability in the CPCA Resource Download process of Canon multifunction printers allows network attackers to crash devices or exe...

May 11, 2023
CVE-2023-24943
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

May 9, 2023
CVE-2022-43634
9.8

CVE-2022-43634 is a critical heap-based buffer overflow vulnerability in Netatalk's dsi_writeinit function that allows unauthenticated remote attacker...

Mar 29, 2023
CVE-2023-25668
9.8

This CVE describes a heap-based buffer overflow vulnerability in TensorFlow that allows attackers to access memory outside user-controlled bounds. Thi...

Mar 25, 2023
CVE-2023-23415
9.8

This critical vulnerability allows remote attackers to execute arbitrary code on affected systems by sending specially crafted ICMP packets. It affect...

Mar 14, 2023
CVE-2023-21689
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft's Protected Extensible Authentication Protocol (PEAP...

Feb 14, 2023
CVE-2023-21692
9.8

This critical vulnerability in Microsoft's Protected Extensible Authentication Protocol (PEAP) allows remote attackers to execute arbitrary code on af...

Feb 14, 2023
CVE-2022-1253
9.8

CVE-2022-1253 is a heap-based buffer overflow vulnerability in libde265, an open-source H.265/HEVC video codec implementation. This vulnerability allo...

Apr 6, 2022
CVE-2022-0631
9.8

CVE-2022-0631 is a heap-based buffer overflow vulnerability in mruby (a lightweight Ruby implementation) that allows attackers to execute arbitrary co...

Feb 18, 2022
CVE-2022-0318
9.8

CVE-2022-0318 is a heap-based buffer overflow vulnerability in Vim text editor versions prior to 8.2. This allows attackers to execute arbitrary code ...

Jan 21, 2022
CVE-2022-0080
9.8

CVE-2022-0080 is a heap-based buffer overflow vulnerability in mruby, a lightweight implementation of the Ruby programming language. Attackers can exp...

Jan 2, 2022
CVE-2021-24041
9.8

A missing bounds check in WhatsApp's image blurring code allows an attacker to trigger an out-of-bounds write by sending a malicious image. This could...

Dec 7, 2021
CVE-2021-3756
9.8

CVE-2021-3756 is a heap-based buffer overflow vulnerability in libmysofa, a library for reading HRTF (Head-Related Transfer Function) SOFA files. Atta...

Oct 29, 2021
CVE-2021-21825
9.8

This vulnerability allows remote code execution via a heap-based buffer overflow when processing specially crafted XMI files in Xmill 0.7. Attackers c...

Aug 18, 2021
CVE-2021-21810
9.8

CVE-2021-21810 is a critical heap buffer overflow vulnerability in Xmill 0.7's XML parser that allows attackers to execute arbitrary code or cause den...

Aug 17, 2021
CVE-2021-21829
9.8

CVE-2021-21829 is a critical heap-based buffer overflow vulnerability in Xmill 0.7's XML decompression functionality that allows remote code execution...

Aug 13, 2021
CVE-2021-24036
9.8

This CVE describes an integer overflow vulnerability in Facebook's folly library that affects HHVM. An attacker can pass a controlled size when creati...

Jul 23, 2021
CVE-2021-21795
9.8

A heap-based buffer overflow vulnerability in Accusoft ImageGear's PSD parsing allows remote code execution when processing malicious files. This affe...

Jun 11, 2021
CVE-2021-26691
9.8

CVE-2021-26691 is a critical heap overflow vulnerability in Apache HTTP Server that allows remote attackers to execute arbitrary code or cause denial ...

Jun 10, 2021
CVE-2021-25668
9.8

This vulnerability in Siemens SCALANCE industrial switches allows attackers to send specially crafted POST requests that cause heap memory corruption....

Apr 22, 2021
CVE-2020-27297
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected OPC UA Tunneller systems through a heap-based buffer overflow. Attack...

Jan 26, 2021
CVE-2020-15800
9.8

A heap overflow vulnerability in the webserver of Siemens SCALANCE X-200 and X-300 industrial switches allows remote attackers to crash the webserver ...

Jan 12, 2021
CVE-2020-27251
9.8

A heap overflow vulnerability in FactoryTalk Linx versions 6.11 and earlier allows remote, unauthenticated attackers to send malicious port ranges tha...

Nov 26, 2020
CVE-2021-3625
9.6

CVE-2021-3625 is a heap-based buffer overflow vulnerability in Zephyr RTOS's USB Device Firmware Upgrade (DFU) DNLOAD functionality. This allows attac...

Oct 5, 2021
CVE-2025-30216
9.4

A heap overflow vulnerability in CryptoLib's TM protocol processing allows attackers to trigger arbitrary memory overwrites by sending specially craft...

Mar 25, 2025
CVE-2025-54574
9.3

Squid caching proxy versions 6.3 and below contain a heap buffer overflow vulnerability in URN processing that could allow remote attackers to execute...

Aug 1, 2025
CVE-2025-62608
9.1

CVE-2025-62608 is a heap buffer overflow vulnerability in MLX's load() function when parsing malicious NumPy .npy files. Attackers can trigger a 13-by...

Nov 21, 2025
CVE-2025-58050
9.1

A heap-buffer-overflow read vulnerability in PCRE2 library version 10.45 allows attackers to read out-of-bounds memory when processing specific regula...

Aug 27, 2025
CVE-2025-23317
9.1

NVIDIA Triton Inference Server's HTTP server has a heap-based buffer overflow vulnerability (CWE-122) that allows attackers to execute arbitrary code ...

Aug 6, 2025
CVE-2023-5841
9.1

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting a heap-based buffer overflow in OpenEXR image p...

Feb 1, 2024
CVE-2023-5908
9.1

CVE-2023-5908 is a buffer overflow vulnerability in KEPServerEX that could allow attackers to crash the software or leak sensitive information. This a...

Nov 30, 2023
CVE-2022-31003
9.1

CVE-2022-31003 is a heap-based buffer overflow vulnerability in Sofia-SIP library's SDP parsing that allows out-of-bounds memory writes. Attackers can...

May 31, 2022
CVE-2020-27263
9.1

A heap-based buffer overflow vulnerability in multiple industrial OPC UA server products allows attackers to crash servers and potentially leak data b...

Jan 14, 2021
CVE-2025-8351
9.0

A heap-based buffer overflow and out-of-bounds read vulnerability in Avast Antivirus for macOS allows local attackers to execute arbitrary code or cau...

Dec 1, 2025
CVE-2025-20363
9.0

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Cisco devices. Unauthenticated attacker...

Sep 25, 2025
CVE-2023-29125
9.0

CVE-2023-29125 is a heap buffer overflow vulnerability in TCP port 7700 services that allows remote attackers to execute arbitrary code or cause denia...

Nov 5, 2024

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 834 CVEs classified as CWE-122, with 106 rated critical and 649 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free