CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

846
Total CVEs
107
Critical
660
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (846)

CVE-2025-0755
8.4

A buffer overflow vulnerability in MongoDB's C driver library (libbson) allows attackers to cause segmentation faults and application crashes by creat...

Mar 18, 2025
CVE-2024-45679
8.4

A heap-based buffer overflow vulnerability in Assimp versions before 5.4.3 allows local attackers to execute arbitrary code by importing a specially c...

Sep 18, 2024
CVE-2023-52168
8.4

A heap-based buffer overflow vulnerability in 7-Zip's NTFS handler allows attackers to write two bytes beyond allocated buffer boundaries when process...

Jul 3, 2024
CVE-2024-24334
8.4

A heap buffer overflow vulnerability in the dfs_v2 dfs_file component of RT-Thread allows attackers to execute arbitrary code or cause denial of servi...

Mar 27, 2024
CVE-2024-25390
8.4

A heap buffer overflow vulnerability in RT-Thread's command shell components allows attackers to execute arbitrary code or cause denial of service. Th...

Mar 27, 2024
CVE-2024-27209
8.4

CVE-2024-27209 is a heap buffer overflow vulnerability in Android that allows local privilege escalation without user interaction. Attackers can explo...

Mar 11, 2024
CVE-2023-6246
8.4

A heap-based buffer overflow in glibc's syslog functions allows attackers to crash applications or potentially escalate privileges locally. This affec...

Jan 31, 2024
CVE-2023-37297
8.3

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to trigger heap memory corruption via CWE-122 (Heap-based Buffer Overflow). ...

Jan 9, 2024
CVE-2023-37295
8.3

This vulnerability in AMI's SPx BMC allows attackers on adjacent networks to cause heap memory corruption, potentially leading to remote code executio...

Jan 9, 2024
CVE-2026-25794
8.2

This vulnerability in ImageMagick allows attackers to trigger an integer overflow when processing large UHDR images, leading to heap buffer overflow a...

Feb 24, 2026
CVE-2025-61553
8.2

This vulnerability allows local attackers to trigger an out-of-bounds write in BitVisor's VirtIO network device emulation, potentially causing hypervi...

Oct 16, 2025
CVE-2025-1943
8.2

CVE-2025-1943 is a heap-based buffer overflow vulnerability in Firefox and Thunderbird that could allow memory corruption. Attackers could potentially...

Mar 4, 2025
CVE-2023-31276
8.2

A heap-based buffer overflow vulnerability in BMC firmware for specific Intel server boards allows privileged users to escalate privileges via local a...

Feb 12, 2025
CVE-2025-0611
8.2

This vulnerability in Chrome's V8 JavaScript engine allows object corruption that could lead to heap corruption when processing malicious HTML pages. ...

Jan 22, 2025
CVE-2023-39946
8.2

CVE-2023-39946 is a heap overflow vulnerability in eprosima Fast DDS that allows remote attackers to crash any Fast-DDS process by sending a specially...

Aug 11, 2023
CVE-2021-3835
8.2

This CVE describes a heap-based buffer overflow vulnerability in the USB device class implementation in Zephyr RTOS. Attackers could exploit this to e...

Feb 7, 2022
CVE-2021-31428
8.2

This is a heap-based buffer overflow vulnerability in Parallels Desktop's IDE virtual device that allows local attackers with high-privileged code exe...

Apr 29, 2021
CVE-2026-20777
8.1

A heap-based buffer overflow vulnerability in libbiosig's Nicolet WFT file parser allows arbitrary code execution when processing malicious .wft files...

Mar 3, 2026
CVE-2025-57709
8.1

A buffer overflow vulnerability in Qsync Central allows authenticated remote attackers to modify memory or crash processes. This affects all Qsync Cen...

Feb 11, 2026
CVE-2026-23876
8.1

A heap buffer overflow vulnerability in ImageMagick's XBM image decoder allows attackers to write controlled data beyond allocated memory boundaries w...

Jan 20, 2026
CVE-2025-25249
8.1

A heap-based buffer overflow vulnerability in multiple Fortinet products allows attackers to execute arbitrary code or commands via specially crafted ...

Jan 13, 2026
CVE-2025-10101
8.1

A heap-based buffer overflow vulnerability in Avast Antivirus for macOS allows local attackers to execute arbitrary code or cause denial of service by...

Dec 1, 2025
CVE-2025-11458
8.1

A heap buffer overflow vulnerability in Google Chrome's Sync component allows remote attackers to perform out-of-bounds memory reads via a crafted HTM...

Nov 6, 2025
CVE-2025-3320
8.1

CVE-2025-3320 is a heap-based buffer overflow vulnerability in IBM Tivoli Monitoring that allows remote attackers to execute arbitrary code or crash t...

Aug 6, 2025
CVE-2025-21376
8.1

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable LDAP implementations. Attackers can exploit...

Feb 11, 2025
CVE-2024-6873
8.1

CVE-2024-6873 is a heap-based buffer overflow vulnerability in ClickHouse's native interface that allows unauthenticated attackers to crash the server...

Aug 1, 2024
CVE-2024-30020
8.1

This vulnerability in Windows Cryptographic Services allows remote attackers to execute arbitrary code on affected systems by sending specially crafte...

May 14, 2024
CVE-2023-5400
8.1

CVE-2023-5400 is a heap overflow vulnerability in Honeywell products where a malformed message with specific key values can cause memory corruption. T...

Apr 17, 2024
CVE-2024-25262
8.1

A heap buffer overflow vulnerability exists in texlive-bin's ttfdump tool via the ttfLoadHDMX function. Attackers can exploit this by providing a spec...

Feb 29, 2024
CVE-2022-26098
8.1

CVE-2022-26098 is a heap-based buffer overflow vulnerability in the sheifd_create function of Samsung's libsimba library that allows remote attackers ...

Apr 11, 2022
CVE-2022-27568
8.1

A heap-based buffer overflow vulnerability in the parser_iloc function of Samsung's libsimba library allows remote attackers to execute arbitrary code...

Apr 11, 2022
CVE-2022-27570
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Samsung devices through a heap-based buffer overflow in the libsimba ...

Apr 11, 2022
CVE-2022-27572
8.1

A heap-based buffer overflow vulnerability in the parser_ipma function of Samsung's libsimba library allows remote attackers to execute arbitrary code...

Apr 11, 2022
CVE-2021-21962
8.1

CVE-2021-21962 is a heap-based buffer overflow vulnerability in the OTA Update functionality of Sealevel Systems SeaConnect 370W. Attackers can exploi...

Feb 4, 2022
CVE-2021-32959
8.1

This vulnerability is a heap-based buffer overflow in the SuiteLink server when processing commands 0x05/0x06. It allows remote attackers to execute a...

Sep 23, 2021
CVE-2020-25681
8.1

This vulnerability is a heap-based buffer overflow in dnsmasq before version 2.83 that occurs during DNSSEC validation of RRSets. An attacker who can ...

Jan 20, 2021
CVE-2025-62673
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows attackers on the same network to crash the device or potentially...

Feb 3, 2026
CVE-2025-58455
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

Feb 3, 2026
CVE-2025-59482
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

Feb 3, 2026
CVE-2025-59487
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

Feb 3, 2026
CVE-2025-61944
8.0

A heap-based buffer overflow in TP-Link Archer AX53 v1.0's tmpserver modules allows authenticated attackers on the same network to crash the device or...

Feb 3, 2026
CVE-2025-61983
8.0

A heap-based buffer overflow in TP-Link Archer AX53 v1.0's tmpserver modules allows authenticated attackers on the same network to crash the device or...

Feb 3, 2026
CVE-2025-62404
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

Feb 3, 2026
CVE-2025-62405
8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

Feb 3, 2026
CVE-2025-58077
8.0

This CVE describes a heap-based buffer overflow in the tmpserver modules of TP-Link Archer AX53 v1.0 routers. Authenticated attackers on the same loca...

Feb 3, 2026
CVE-2025-36923
8.0

This CVE describes a heap buffer overflow vulnerability in the NrmmDecoder component of Android's media framework. An attacker could exploit this to e...

Dec 11, 2025
CVE-2025-62452
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Nov 11, 2025
CVE-2025-60715
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Nov 11, 2025
CVE-2025-20742
8.0

This CVE describes a critical vulnerability in MediaTek WLAN AP drivers where an incorrect bounds check allows out-of-bounds write. Attackers within w...

Nov 4, 2025
CVE-2025-53720
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Aug 12, 2025

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free