CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

846
Total CVEs
107
Critical
660
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (846)

CVE-2024-38212
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) by sending sp...

Oct 8, 2024
CVE-2024-8636
8.8

This vulnerability is a heap buffer overflow in Chrome's Skia graphics engine that allows remote attackers to potentially exploit heap corruption via ...

Sep 11, 2024
CVE-2024-8198
8.8

This heap buffer overflow vulnerability in Chrome's Skia graphics engine allows attackers who have already compromised the renderer process to potenti...

Aug 28, 2024
CVE-2024-8193
8.8

This vulnerability allows remote attackers to exploit heap corruption in Chrome's Skia graphics engine via a crafted HTML page. Attackers who have alr...

Aug 28, 2024
CVE-2024-7967
8.8

A heap buffer overflow vulnerability in Chrome's font processing allows remote attackers to potentially execute arbitrary code or cause denial of serv...

Aug 21, 2024
CVE-2024-7973
8.8

A heap buffer overflow vulnerability in Chrome's PDFium PDF rendering engine allows remote attackers to perform out-of-bounds memory reads via malicio...

Aug 21, 2024
CVE-2024-38154
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Aug 13, 2024
CVE-2024-38130
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Aug 13, 2024
CVE-2024-38120
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...

Aug 13, 2024
CVE-2024-38116
8.8

This vulnerability allows remote code execution through the Windows IP Routing Management Snapin. Attackers can exploit this to execute arbitrary code...

Aug 13, 2024
CVE-2024-38114
8.8

This vulnerability allows remote code execution through the Windows IP Routing Management Snapin. Attackers can exploit this to execute arbitrary code...

Aug 13, 2024
CVE-2024-6994
8.8

This vulnerability allows remote attackers to trigger heap corruption via a crafted HTML page in Google Chrome's layout engine. Attackers could potent...

Aug 6, 2024
CVE-2024-39883
8.8

Delta Electronics CNCSoft-G2 has a heap-based buffer overflow vulnerability due to improper length validation of user-supplied data. Attackers can exp...

Jul 9, 2024
CVE-2024-37332
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-37334
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Jul 9, 2024
CVE-2024-37328
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-37330
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-37321
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-37326
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provide...

Jul 9, 2024
CVE-2024-35271
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests...

Jul 9, 2024
CVE-2024-37319
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests...

Jul 9, 2024
CVE-2024-21449
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provide...

Jul 9, 2024
CVE-2024-21414
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-21425
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-21333
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-21373
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-21331
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-20701
8.8

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specia...

Jul 9, 2024
CVE-2024-30017
8.8

This vulnerability allows an authenticated attacker on a guest virtual machine to execute arbitrary code on the Hyper-V host. It affects Windows syste...

May 14, 2024
CVE-2024-33877
8.8

CVE-2024-33877 is a heap-based buffer overflow vulnerability in the HDF5 library's H5T__conv_struct_opt function. This allows attackers to execute arb...

May 14, 2024
CVE-2024-33873
8.8

CVE-2024-33873 is a heap-based buffer overflow vulnerability in the HDF5 library's H5D__scatter_mem function. This allows attackers to execute arbitra...

May 14, 2024
CVE-2024-32623
8.8

CVE-2024-32623 is a heap-based buffer overflow vulnerability in the HDF5 library's H5VM_array_fill function. This allows attackers to execute arbitrar...

May 14, 2024
CVE-2024-32617
8.8

CVE-2024-32617 is a heap-based buffer over-read vulnerability in the HDF5 library that could allow attackers to read sensitive memory contents or caus...

May 14, 2024
CVE-2024-32605
8.8

This vulnerability in the HDF5 library allows attackers to read beyond allocated heap memory boundaries when processing specially crafted HDF5 files. ...

May 14, 2024
CVE-2024-29161
8.8

CVE-2024-29161 is a heap buffer overflow vulnerability in HDF5 library versions through 1.14.3 that can corrupt the instruction pointer when processin...

May 14, 2024
CVE-2023-44429
8.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in GStreamer's AV1 codec parser. Attac...

May 3, 2024
CVE-2023-41229
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-3040 routers without authentication. Attackers ca...

May 3, 2024
CVE-2023-37329
8.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow in GStreamer's SRT subtitle file parse...

May 3, 2024
CVE-2024-33428
8.8

A heap buffer overflow vulnerability in phiola's WAV file parser allows remote attackers to execute arbitrary code by sending a specially crafted .wav...

May 1, 2024
CVE-2024-29982
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-29984
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-29048
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-29044
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-29046
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-28940
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-28932
8.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially ...

Apr 9, 2024
CVE-2024-28927
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-28914
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-28910
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft OLE DB Driver for SQL Server by sending specially craf...

Apr 9, 2024
CVE-2024-28912
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free