CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (846)
This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...
Oct 8, 2024This vulnerability is a heap buffer overflow in Chrome's Skia graphics engine that allows remote attackers to potentially exploit heap corruption via ...
Sep 11, 2024This heap buffer overflow vulnerability in Chrome's Skia graphics engine allows attackers who have already compromised the renderer process to potenti...
Aug 28, 2024This vulnerability allows remote attackers to exploit heap corruption in Chrome's Skia graphics engine via a crafted HTML page. Attackers who have alr...
Aug 28, 2024A heap buffer overflow vulnerability in Chrome's font processing allows remote attackers to potentially execute arbitrary code or cause denial of serv...
Aug 21, 2024A heap buffer overflow vulnerability in Chrome's PDFium PDF rendering engine allows remote attackers to perform out-of-bounds memory reads via malicio...
Aug 21, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...
Aug 13, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...
Aug 13, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...
Aug 13, 2024This vulnerability allows remote code execution through the Windows IP Routing Management Snapin. Attackers can exploit this to execute arbitrary code...
Aug 13, 2024This vulnerability allows remote code execution through the Windows IP Routing Management Snapin. Attackers can exploit this to execute arbitrary code...
Aug 13, 2024This vulnerability allows remote attackers to trigger heap corruption via a crafted HTML page in Google Chrome's layout engine. Attackers could potent...
Aug 6, 2024Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability due to improper length validation of user-supplied data. Attackers can exp...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provide...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests...
Jul 9, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provide...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...
Jul 9, 2024This vulnerability allows an authenticated attacker on a guest virtual machine to execute arbitrary code on the Hyper-V host. It affects Windows syste...
May 14, 2024CVE-2024-33877 is a heap-based buffer overflow vulnerability in the HDF5 library's H5T__conv_struct_opt function. This allows attackers to execute arb...
May 14, 2024CVE-2024-33873 is a heap-based buffer overflow vulnerability in the HDF5 library's H5D__scatter_mem function. This allows attackers to execute arbitra...
May 14, 2024CVE-2024-32623 is a heap-based buffer overflow vulnerability in the HDF5 library's H5VM_array_fill function. This allows attackers to execute arbitrar...
May 14, 2024CVE-2024-32617 is a heap-based buffer over-read vulnerability in the HDF5 library that could allow attackers to read sensitive memory contents or caus...
May 14, 2024This vulnerability in the HDF5 library allows attackers to read beyond allocated heap memory boundaries when processing specially crafted HDF5 files. ...
May 14, 2024CVE-2024-29161 is a heap buffer overflow vulnerability in HDF5 library versions through 1.14.3 that can corrupt the instruction pointer when processin...
May 14, 2024This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in GStreamer's AV1 codec parser. Attac...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-3040 routers without authentication. Attackers ca...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in GStreamer's SRT subtitle file parse...
May 3, 2024A heap buffer overflow vulnerability in phiola's WAV file parser allows remote attackers to execute arbitrary code by sending a specially crafted .wav...
May 1, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially ...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft OLE DB Driver for SQL Server by sending specially craf...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free