CWE-122: Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

846
Total CVEs
107
Critical
660
High
8.0
Avg CVSS
5
In CISA KEV

Yearly Trend

2026
84
2025
311
2024
248
2023
84
2022
58

Top Affected Vendors

1 Microsoft 262
2 Adobe 85
3 Fedoraproject 32
4 Google 31
5 Debian 27
6 Vim 23
7 Siemens 17
8 Mediatek 14
9 Autodesk 14
10 Hdfgroup 13

All Heap-based Buffer Overflow CVEs (846)

CVE-2025-50160
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Aug 12, 2025
CVE-2025-50162
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Aug 12, 2025
CVE-2025-50164
8.0

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows authenticated attackers to execute arbitrary cod...

Aug 12, 2025
CVE-2025-49691
8.0

A heap-based buffer overflow vulnerability in Windows Media allows attackers on the same network to execute arbitrary code on vulnerable systems. This...

Jul 8, 2025
CVE-2023-28905
8.0

A heap buffer overflow vulnerability in the image processing component of Volkswagen MIB3 infotainment systems allows attackers to execute arbitrary c...

Jun 28, 2025
CVE-2025-27487
8.0

A heap-based buffer overflow vulnerability in Microsoft Remote Desktop Client allows authenticated attackers to execute arbitrary code remotely by sen...

Apr 8, 2025
CVE-2024-46461
8.0

CVE-2024-46461 is an integer overflow vulnerability in VLC media player that allows denial of service or arbitrary code execution when processing mali...

Sep 25, 2024
CVE-2024-37987
8.0

This Secure Boot vulnerability allows attackers to bypass security features and execute unauthorized code during the boot process. It affects systems ...

Jul 9, 2024
CVE-2024-30074
8.0

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Link Laye...

Jun 11, 2024
CVE-2024-30077
8.0

CVE-2024-30077 is a remote code execution vulnerability in Windows OLE (Object Linking and Embedding) technology. Attackers can exploit this by tricki...

Jun 11, 2024
CVE-2023-50230
8.0

This CVE describes a heap-based buffer overflow vulnerability in BlueZ's Phone Book Access Profile that allows network-adjacent attackers to execute a...

May 3, 2024
CVE-2023-49501
8.0

A buffer overflow vulnerability in FFmpeg's config_eq_output function allows local attackers to execute arbitrary code. This affects systems running v...

Apr 19, 2024
CVE-2023-49528
8.0

A buffer overflow vulnerability in FFmpeg's de_stereo component allows local attackers to execute arbitrary code or cause denial of service. This affe...

Apr 12, 2024
CVE-2021-3968
8.0

CVE-2021-3968 is a heap-based buffer overflow vulnerability in Vim text editor that allows attackers to execute arbitrary code by tricking users into ...

Nov 19, 2021
CVE-2025-62526
7.9

CVE-2025-62526 is a heap buffer overflow vulnerability in OpenWrt's ubusd daemon that allows attackers to execute arbitrary code with ubus daemon priv...

Oct 22, 2025
CVE-2026-2047
7.8

This CVE describes a heap-based buffer overflow vulnerability in GIMP's ICNS file parser that allows remote code execution. Attackers can exploit this...

Feb 20, 2026
CVE-2026-26200
7.8

This CVE describes a heap buffer overflow vulnerability in HDF5 software that allows attackers to trigger denial-of-service conditions through special...

Feb 19, 2026
CVE-2026-21357
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow an attacker to execute arbitrary code with the privil...

Feb 10, 2026
CVE-2026-21259
7.8

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows local attackers to execute arbitrary code with elevated privileges. This a...

Feb 10, 2026
CVE-2026-21246
7.8

A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows authenticated attackers to execute arbitrary code with elevated priv...

Feb 10, 2026
CVE-2026-21245
7.8

A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...

Feb 10, 2026
CVE-2026-21239
7.8

A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...

Feb 10, 2026
CVE-2026-23719
7.8

A heap-based buffer overflow vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into ...

Feb 10, 2026
CVE-2026-1283
7.8

A heap-based buffer overflow vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. Th...

Jan 26, 2026
CVE-2025-15059
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in GIMP. The heap-based buffer...

Jan 23, 2026
CVE-2026-21283
7.8

Adobe Bridge versions 15.1.2, 16.0 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a use...

Jan 13, 2026
CVE-2026-21304
7.8

CVE-2026-21304 is a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens ...

Jan 13, 2026
CVE-2026-21277
7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe InDesign that could allow attackers to execute arbitrary code when a user opens...

Jan 13, 2026
CVE-2026-21281
7.8

A heap-based buffer overflow vulnerability in Adobe InCopy allows arbitrary code execution when a user opens a malicious file. This affects users runn...

Jan 13, 2026
CVE-2026-20957
7.8

An integer underflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by opening specially craft...

Jan 13, 2026
CVE-2026-20922
7.8

A heap-based buffer overflow vulnerability in Windows NTFS allows authenticated attackers to execute arbitrary code locally on affected systems. This ...

Jan 13, 2026
CVE-2026-20864
7.8

This vulnerability is a heap-based buffer overflow in the Connected Devices Platform Service (Cdpsvc) on Windows systems. It allows an authenticated a...

Jan 13, 2026
CVE-2026-20840
7.8

A heap-based buffer overflow vulnerability in Windows NTFS allows authenticated attackers to execute arbitrary code locally on affected systems. This ...

Jan 13, 2026
CVE-2026-20837
7.8

A heap-based buffer overflow vulnerability in Windows Media allows local attackers to execute arbitrary code on affected systems. This affects Windows...

Jan 13, 2026
CVE-2026-20820
7.8

This vulnerability is a heap-based buffer overflow in the Windows Common Log File System Driver that allows an authenticated attacker to execute arbit...

Jan 13, 2026
CVE-2026-20809
7.8

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the Windows Kernel Memory allows authenticated attackers to escalate privileges l...

Jan 13, 2026
CVE-2025-15277
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SGI image files in FontForge. Attackers ...

Dec 31, 2025
CVE-2025-15279
7.8

A heap-based buffer overflow vulnerability in FontForge's BMP file parsing allows remote attackers to execute arbitrary code when users open malicious...

Dec 31, 2025
CVE-2025-14425
7.8

This vulnerability in GIMP allows remote attackers to execute arbitrary code by tricking users into opening malicious JP2 image files. The flaw exists...

Dec 23, 2025
CVE-2025-12495
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems runn...

Dec 23, 2025
CVE-2025-12839
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems runn...

Dec 23, 2025
CVE-2025-12840
7.8

This is a heap-based buffer overflow vulnerability in Academy Software Foundation OpenEXR's EXR file parsing. Attackers can execute arbitrary code by ...

Dec 23, 2025
CVE-2025-14935
7.8

This is a heap-based buffer overflow vulnerability in NSF Unidata NetCDF-C library that allows remote code execution when processing malicious files. ...

Dec 23, 2025
CVE-2025-9457
7.8

A memory corruption vulnerability in Autodesk products allows arbitrary code execution when parsing malicious PRT files. Attackers can exploit this to...

Dec 16, 2025
CVE-2025-10881
7.8

This vulnerability allows attackers to exploit a heap-based buffer overflow when Autodesk products parse malicious CATPRODUCT files. Successful exploi...

Dec 16, 2025
CVE-2025-64679
7.8

A heap-based buffer overflow vulnerability in Windows Desktop Window Manager (DWM) Core Library allows authenticated attackers to execute arbitrary co...

Dec 9, 2025
CVE-2025-64680
7.8

CVE-2025-64680 is a heap-based buffer overflow vulnerability in the Windows Desktop Window Manager (DWM) Core Library that allows authenticated attack...

Dec 9, 2025
CVE-2025-46373
7.8

A heap-based buffer overflow vulnerability in Fortinet FortiClient for Windows allows authenticated local IPSec users to execute arbitrary code or com...

Nov 18, 2025
CVE-2025-61837
7.8

Format Plugins versions 1.1.1 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a us...

Nov 11, 2025
CVE-2025-61838
7.8

Format Plugins versions 1.1.1 and earlier contain a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user ope...

Nov 11, 2025

About Heap-based Buffer Overflow (CWE-122)

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.

Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.

External reference: View CWE-122 on MITRE CWE →

Monitor Heap-based Buffer Overflow Vulnerabilities

Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.

Start Monitoring Free