CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (846)
A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...
Aug 12, 2025A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...
Aug 12, 2025A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...
Aug 12, 2025A heap-based buffer overflow vulnerability in Windows Media allows attackers on the same network to execute arbitrary code on vulnerable systems. This...
Jul 8, 2025A heap buffer overflow vulnerability in the image processing component of Volkswagen MIB3 infotainment systems allows attackers to execute arbitrary c...
Jun 28, 2025A heap-based buffer overflow vulnerability in Microsoft Remote Desktop Client allows authenticated attackers to execute arbitrary code remotely by sen...
Apr 8, 2025CVE-2024-46461 is an integer overflow vulnerability in VLC media player that allows denial of service or arbitrary code execution when processing mali...
Sep 25, 2024This Secure Boot vulnerability allows attackers to bypass security features and execute unauthorized code during the boot process. It affects systems ...
Jul 9, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Link Laye...
Jun 11, 2024CVE-2024-30077 is a remote code execution vulnerability in Windows OLE (Object Linking and Embedding) technology. Attackers can exploit this by tricki...
Jun 11, 2024This CVE describes a heap-based buffer overflow vulnerability in BlueZ's Phone Book Access Profile that allows network-adjacent attackers to execute a...
May 3, 2024A buffer overflow vulnerability in FFmpeg's config_eq_output function allows local attackers to execute arbitrary code. This affects systems running v...
Apr 19, 2024A buffer overflow vulnerability in FFmpeg's de_stereo component allows local attackers to execute arbitrary code or cause denial of service. This affe...
Apr 12, 2024CVE-2021-3968 is a heap-based buffer overflow vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into ...
Nov 19, 2021CVE-2025-62526 is a heap buffer overflow vulnerability in OpenWrt's ubusd daemon that allows attackers to execute arbitrary code with ubus daemon priv...
Oct 22, 2025This CVE describes a heap-based buffer overflow vulnerability in GIMP's ICNS file parser that allows remote code execution. Attackers can exploit this...
Feb 20, 2026This CVE describes a heap buffer overflow vulnerability in HDF5 software that allows attackers to trigger denial-of-service conditions through special...
Feb 19, 2026This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privil...
Feb 10, 2026A heap-based buffer overflow vulnerability in Microsoft Office Excel allows local attackers to execute arbitrary code with elevated privileges. This a...
Feb 10, 2026A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows authenticated attackers to execute arbitrary code with elevated priv...
Feb 10, 2026A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...
Feb 10, 2026A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...
Feb 10, 2026A heap-based buffer overflow vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into ...
Feb 10, 2026A heap-based buffer overflow vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. Th...
Jan 26, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in GIMP. The heap-based buffer...
Jan 23, 2026Adobe Bridge versions 15.1.2, 16.0 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a use...
Jan 13, 2026CVE-2026-21304 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens ...
Jan 13, 2026This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens...
Jan 13, 2026A heap-based buffer overflow vulnerability in Adobe InCopy allows arbitrary code execution when a user opens a malicious file. This affects users runn...
Jan 13, 2026An integer underflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by opening specially craft...
Jan 13, 2026A heap-based buffer overflow vulnerability in Windows NTFS allows authenticated attackers to execute arbitrary code locally on affected systems. This ...
Jan 13, 2026This vulnerability is a heap-based buffer overflow in the Connected Devices Platform Service (Cdpsvc) on Windows systems. It allows an authenticated a...
Jan 13, 2026A heap-based buffer overflow vulnerability in Windows NTFS allows authenticated attackers to execute arbitrary code locally on affected systems. This ...
Jan 13, 2026A heap-based buffer overflow vulnerability in Windows Media allows local attackers to execute arbitrary code on affected systems. This affects Windows...
Jan 13, 2026This vulnerability is a heap-based buffer overflow in the Windows Common Log File System Driver that allows an authenticated attacker to execute arbit...
Jan 13, 2026A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the Windows Kernel Memory allows authenticated attackers to escalate privileges l...
Jan 13, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SGI image files in FontForge. Attackers ...
Dec 31, 2025A heap-based buffer overflow vulnerability in FontForge's BMP file parsing allows remote attackers to execute arbitrary code when users open malicious...
Dec 31, 2025This vulnerability in GIMP allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files. The flaw exists...
Dec 23, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems runn...
Dec 23, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems runn...
Dec 23, 2025This is a heap-based buffer overflow vulnerability in Academy Software Foundation OpenEXR's EXR file parsing. Attackers can execute arbitrary code by ...
Dec 23, 2025This is a heap-based buffer overflow vulnerability in NSF Unidata NetCDF-C library that allows remote code execution when processing malicious files. ...
Dec 23, 2025A memory corruption vulnerability in Autodesk products allows arbitrary code execution when parsing malicious PRT files. Attackers can exploit this to...
Dec 16, 2025This vulnerability allows attackers to exploit a heap-based buffer overflow when Autodesk products parse malicious CATPRODUCT files. Successful exploi...
Dec 16, 2025A heap-based buffer overflow vulnerability in Windows Desktop Window Manager (DWM) Core Library allows authenticated attackers to execute arbitrary co...
Dec 9, 2025CVE-2025-64680 is a heap-based buffer overflow vulnerability in the Windows Desktop Window Manager (DWM) Core Library that allows authenticated attack...
Dec 9, 2025A heap-based buffer overflow vulnerability in Fortinet FortiClient for Windows allows authenticated local IPSec users to execute arbitrary code or com...
Nov 18, 2025Format Plugins versions 1.1.1 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a us...
Nov 11, 2025Format Plugins versions 1.1.1 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user ope...
Nov 11, 2025About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free