CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

846
Total CVEs
107
Critical
660
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (846)

CVE-2025-21369
8.8

This vulnerability allows remote code execution via Microsoft Digest Authentication, enabling attackers to execute arbitrary code on affected systems....

Feb 11, 2025
CVE-2025-21371
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Feb 11, 2025
CVE-2025-21208
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Routing and Remote Access Service (RRAS) by exploi...

Feb 11, 2025
CVE-2025-21190
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Feb 11, 2025
CVE-2019-15690
8.8

CVE-2019-15690 is a heap buffer overflow vulnerability in LibVNCServer that allows remote attackers to execute arbitrary code by sending specially cra...

Jan 24, 2025
CVE-2023-50739
8.8

A buffer overflow vulnerability in Lexmark devices' Internet Printing Protocol (IPP) allows attackers to execute arbitrary code remotely. This affects...

Jan 18, 2025
CVE-2025-0434
8.8

This vulnerability allows a remote attacker to trigger out-of-bounds memory access in Chrome's V8 JavaScript engine, potentially leading to heap corru...

Jan 15, 2025
CVE-2025-21413
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21417
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21409
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21411
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21339
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21303
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code on affected systems by sending specially crafted req...

Jan 14, 2025
CVE-2025-21305
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21306
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21302
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21286
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21282
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21273
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code on affected systems by sending specially crafted req...

Jan 14, 2025
CVE-2025-21266
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21252
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21248
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21250
8.8

This is a heap-based buffer overflow vulnerability in the Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM...

Jan 14, 2025
CVE-2025-21245
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21246
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21241
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code on affected systems by sending specially crafted req...

Jan 14, 2025
CVE-2025-21239
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21240
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code with SYSTEM privileges by sending specially crafted ...

Jan 14, 2025
CVE-2025-21238
8.8

This is a heap-based buffer overflow vulnerability in Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM pri...

Jan 14, 2025
CVE-2025-21236
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21237
8.8

This is a heap-based buffer overflow vulnerability in the Windows Telephony Service that allows remote attackers to execute arbitrary code with SYSTEM...

Jan 14, 2025
CVE-2025-21233
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a heap-based buffer overflow in the Telephony Se...

Jan 14, 2025
CVE-2025-21223
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code on affected systems by sending specially crafted req...

Jan 14, 2025
CVE-2025-21178
8.8

This is a heap-based buffer overflow vulnerability in Visual Studio that allows remote code execution when processing specially crafted files. Attacke...

Jan 14, 2025
CVE-2024-56737
8.8

CVE-2024-56737 is a heap-based buffer overflow vulnerability in GNU GRUB2's HFS filesystem parser. Attackers can exploit this by providing specially c...

Dec 29, 2024
CVE-2024-56732
8.8

CVE-2024-56732 is a heap-based buffer overflow vulnerability in HarfBuzz text shaping engine that could allow attackers to execute arbitrary code or c...

Dec 27, 2024
CVE-2024-49104
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Dec 12, 2024
CVE-2024-49102
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Dec 12, 2024
CVE-2024-49086
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Dec 12, 2024
CVE-2024-6246
8.8

This vulnerability allows attackers on the same network to execute arbitrary code on Wyze Cam v3 IP cameras without authentication. The flaw exists in...

Nov 22, 2024
CVE-2024-49012
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected ...

Nov 12, 2024
CVE-2024-49008
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected ...

Nov 12, 2024
CVE-2024-49010
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected ...

Nov 12, 2024
CVE-2024-49002
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected ...

Nov 12, 2024
CVE-2024-49004
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted network packets. It affe...

Nov 12, 2024
CVE-2024-49006
8.8

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected ...

Nov 12, 2024
CVE-2024-43607
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS). Attackers ca...

Oct 8, 2024
CVE-2024-43589
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...

Oct 8, 2024
CVE-2024-43564
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Oct 8, 2024
CVE-2024-43518
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Telephony Server service. Attackers can exploit th...

Oct 8, 2024

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free