CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (846)
This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...
Apr 9, 2024This vulnerability in Microsoft WDAC SQL Server ODBC Driver allows remote attackers to execute arbitrary code on affected systems by sending specially...
Apr 9, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft WDAC OLE DB provider for SQL Server. Attackers can e...
Apr 9, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Routing and Remote Access Service (RRAS) without a...
Apr 9, 2024This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Routing and Remote Access Service (RRAS) without authe...
Apr 9, 2024This vulnerability in Microsoft WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending s...
Mar 12, 2024This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Mar 12, 2024This vulnerability in Microsoft ODBC Driver allows remote attackers to execute arbitrary code by sending specially crafted requests to affected system...
Mar 12, 2024A heap-based buffer overflow vulnerability in the GGUF library's info->ne functionality of llama.cpp allows remote code execution when processing mali...
Feb 26, 2024This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Feb 13, 2024This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Feb 13, 2024This vulnerability allows remote code execution through the Microsoft WDAC OLE DB provider for SQL Server. An attacker could exploit this by sending s...
Feb 13, 2024This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Feb 13, 2024This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Feb 13, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft's WDAC ODBC Driver. Attackers can exploit this heap-...
Feb 13, 2024This Windows kernel vulnerability allows attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows s...
Feb 13, 2024This vulnerability allows remote code execution through Microsoft ActiveX Data Objects (ADO) when an attacker sends specially crafted requests to an a...
Feb 13, 2024This vulnerability allows remote attackers to execute arbitrary code on systems with Internet Connection Sharing (ICS) enabled by sending specially cr...
Dec 12, 2023This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. Attackers c...
Jul 11, 2023This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending...
Jun 14, 2023This vulnerability allows remote attackers to execute arbitrary code on systems using vulnerable Microsoft PostScript and PCL6 printer drivers. Attack...
Mar 14, 2023This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. Attackers c...
Mar 14, 2023This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow in Microsoft PostS...
Mar 14, 2023This vulnerability allows remote code execution through Microsoft PostScript and PCL6 printer drivers. An attacker could exploit this by sending speci...
Mar 14, 2023This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. An attacker...
Mar 14, 2023CVE-2022-32137 is a heap-based buffer overflow vulnerability in multiple CODESYS products that allows low-privileged remote attackers to cause denial-...
Jun 24, 2022A heap-based buffer overflow vulnerability in libsox's sphere.c start_read() function allows attackers to execute arbitrary code or cause denial of se...
Apr 14, 2022CVE-2021-43304 is a heap buffer overflow vulnerability in ClickHouse's LZ4 compression codec that allows attackers to execute arbitrary code or cause ...
Mar 14, 2022This CVE describes a heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC's PDFLibTool component. An unauthenticated attacker can execu...
Sep 2, 2021This heap-based buffer overflow vulnerability in Adobe Acrobat Reader DC allows an unauthenticated attacker to execute arbitrary code on a victim's sy...
Sep 2, 2021This is a heap-based buffer overflow vulnerability in Netatalk's DSI structure processing that allows unauthenticated attackers on the same network to...
May 21, 2021This is a heap-based buffer overflow vulnerability in Parallels Desktop's Open Tools Gate component that allows local attackers to escalate privileges...
Apr 29, 2021This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR Nighthawk R78...
Apr 14, 2021A heap overflow vulnerability in Accusoft ImageGear's GIF parser allows arbitrary code execution when processing specially crafted GIF files. This aff...
Feb 10, 2021This vulnerability allows remote code execution through specially crafted PCX files in Siemens JT2Go and Teamcenter Visualization software. Attackers ...
Jan 12, 2021This vulnerability allows remote code execution via specially crafted JT files in Siemens JT2Go and Teamcenter Visualization software. Attackers can e...
Jan 12, 2021A heap buffer overflow vulnerability in NASA CryptoLib versions 1.4.0 and prior allows attackers to corrupt heap memory by sending specially crafted t...
Aug 11, 2025An unauthenticated remote attacker can send a crafted DHCP request packet to cause Cisco IOS XE devices with DHCP snooping and endpoint analytics enab...
Mar 27, 2024CVE-2021-38439 is a heap-based buffer overflow vulnerability in GurumDDS that could allow attackers to cause denial-of-service or execute arbitrary co...
May 5, 2022A heap buffer overflow vulnerability exists in the ARK library from Bandisoft when the Ark_DigPathA function processes file paths without proper lengt...
Sep 9, 2021Adobe Photoshop versions 22.1 and earlier contain a heap buffer overflow vulnerability when processing malicious font files. Successful exploitation a...
Jan 13, 2021A buffer overflow vulnerability in some Zoom Apps allows authenticated users to escalate privileges through network access. This affects Zoom Apps use...
Feb 25, 2025A buffer overflow vulnerability in Zoom Workplace Apps and Rooms Clients allows authenticated users to escalate privileges through network access. Thi...
Aug 14, 2024A heap-based buffer overflow vulnerability in Cisco ASA's Clientless SSL VPN portal allows authenticated remote attackers to cause denial of service o...
May 3, 2022A heap buffer overflow vulnerability in Pepper language compiler allows arbitrary code execution or denial of service when processing malicious .pr so...
Dec 3, 2025This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Office applications, potentially leading to local code e...
Jul 8, 2025A heap-based buffer overflow vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on vulnerable systems by tricking users...
Jun 11, 2025A heap-based buffer overflow vulnerability in Microsoft Office allows attackers to execute arbitrary code on affected systems by tricking users into o...
Jun 10, 2025A heap buffer overflow vulnerability in Perl's tr operator when processing non-ASCII characters allows attackers to crash applications or potentially ...
Apr 13, 2025About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free