CWE-122: Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Yearly Trend
Top Affected Vendors
All Heap-based Buffer Overflow CVEs (846)
A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them ...
Nov 11, 2025Adobe Illustrator on iPad versions 3.0.9 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...
Nov 11, 2025Adobe Illustrator on iPad versions 3.0.9 and earlier contain a heap-based buffer overflow vulnerability that could allow attackers to execute arbitrar...
Nov 11, 2025A heap-based buffer overflow vulnerability in Photoshop Desktop allows attackers to execute arbitrary code when a user opens a malicious file. This af...
Nov 11, 2025A heap-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This af...
Nov 11, 2025A heap-based buffer overflow vulnerability in Windows OLE (Object Linking and Embedding) allows local attackers to execute arbitrary code on affected ...
Nov 11, 2025A heap-based buffer overflow vulnerability in Adobe InCopy allows arbitrary code execution when a user opens a malicious file. This affects users of I...
Nov 11, 2025A heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. This affec...
Nov 11, 2025A heap-based buffer overflow vulnerability in Adobe InDesign allows attackers to execute arbitrary code when a user opens a malicious file. This affec...
Nov 11, 2025This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious PRT files in affected Autodesk products. Users ...
Nov 7, 2025This CVE describes a buffer overflow vulnerability in MediaTek's wlan AP driver where improper bounds checking allows out-of-bounds writes. An attacke...
Nov 4, 2025This CVE describes a heap-based buffer overflow vulnerability in MediaTek's WLAN AP driver. An attacker with local user privileges can exploit this to...
Nov 4, 2025This CVE describes a heap-based buffer overflow vulnerability in MediaTek's WLAN STA driver. An attacker with local user privileges can exploit this t...
Nov 4, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious XWD image files in GIMP. The heap-based ...
Oct 29, 2025A heap-based buffer overflow vulnerability in GIMP's HDR file parser allows remote attackers to execute arbitrary code when users open malicious HDR f...
Oct 29, 2025CVE-2025-54268 is a heap-based buffer overflow vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious f...
Oct 15, 2025This vulnerability is a heap-based buffer overflow in the Windows Desktop Window Manager (DWM) Core Library that allows an authenticated attacker to e...
Oct 14, 2025A heap-based buffer overflow vulnerability in the Connected Devices Platform Service (Cdpsvc) allows authenticated attackers to execute arbitrary code...
Oct 14, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite. Att...
Sep 17, 2025A heap-based buffer overflow vulnerability in Autodesk products allows malicious PDF files to cause crashes, leak sensitive data, or execute arbitrary...
Sep 16, 2025A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users ...
Sep 9, 2025This vulnerability allows a local authenticated attacker to elevate privileges on Windows systems by exploiting a heap-based buffer overflow in the Lo...
Sep 9, 2025An integer overflow vulnerability in Windows Hyper-V allows authenticated attackers to escalate privileges on the local system. This affects Windows s...
Sep 9, 2025CVE-2025-26455 is a heap buffer overflow vulnerability in Android's NDK MediaCodec component that allows local privilege escalation without user inter...
Sep 4, 2025This CVE describes a heap buffer overflow vulnerability in the ConvertReductionOp function of darwinn_mlir_converter_aidl.cc that allows local privile...
Sep 4, 2025A heap-based buffer overflow vulnerability in Realtek RTL8811AU wireless driver allows local attackers to escalate privileges from low-privileged user...
Sep 2, 2025A heap-based buffer overflow vulnerability in Ashlar-Vellum CAD software allows attackers to execute arbitrary code by crafting malicious VC6 files. T...
Aug 18, 2025CVE-2025-54217 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious f...
Aug 12, 2025CVE-2025-54219 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious f...
Aug 12, 2025A heap-based buffer overflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of...
Aug 12, 2025CVE-2025-49560 is a heap-based buffer overflow vulnerability in Substance3D Viewer that allows arbitrary code execution when a user opens a malicious ...
Aug 12, 2025A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on affected systems by tricking users ...
Aug 12, 2025A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking user...
Aug 12, 2025This vulnerability is a heap-based buffer overflow in the Kernel Streaming WOW Thunk Service Driver (ksthunk.sys) on Windows systems. It allows an aut...
Aug 12, 2025This vulnerability is a type confusion flaw in Windows Push Notifications that allows an authenticated attacker to execute arbitrary code with elevate...
Aug 12, 2025A heap-based buffer overflow vulnerability in Rockwell Automation Arena Simulation allows attackers to execute arbitrary code or disclose information ...
Aug 5, 2025A heap-based buffer overflow vulnerability in Rockwell Automation Arena Simulation allows attackers to execute arbitrary code or disclose information ...
Aug 5, 2025A heap-based buffer overflow vulnerability in Autodesk products allows attackers to execute arbitrary code by tricking users into opening malicious 3D...
Jul 29, 2025Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability (CWE-122) that could allow arbitrary code exec...
Jul 8, 2025CVE-2025-47125 is a heap-based buffer overflow vulnerability in Adobe Framemaker that could allow attackers to execute arbitrary code when a user open...
Jul 8, 2025Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary cod...
Jul 8, 2025Adobe InDesign versions 19.5.3 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a u...
Jul 8, 2025Adobe InDesign versions 19.5.3 and earlier contain a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code when a u...
Jul 8, 2025A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Microsoft Windows QoS scheduler allows authenticated attackers to escalate privil...
Jul 8, 2025A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows authenticated attackers to execute arbitrary code with elevated priv...
Jul 8, 2025A heap-based buffer overflow vulnerability in the Windows Fast FAT driver allows local attackers to execute arbitrary code with elevated privileges. T...
Jul 8, 2025A heap-based buffer overflow vulnerability in Microsoft MPEG-2 Video Extension allows authenticated attackers to execute arbitrary code locally on aff...
Jul 8, 2025A heap-based buffer overflow vulnerability in VS6Sim.exe within FUJI ELECTRIC's V-SFT and TELLUS software allows attackers to execute arbitrary code b...
Jul 8, 2025CVE-2025-47107 is a heap-based buffer overflow vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a malicious f...
Jun 10, 2025A heap-based buffer overflow vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking user...
Jun 10, 2025About Heap-based Buffer Overflow (CWE-122)
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory.
Our database tracks 846 CVEs classified as CWE-122, with 107 rated critical and 660 rated high severity. The average CVSS score for Heap-based Buffer Overflow vulnerabilities is 8.0.
External reference: View CWE-122 on MITRE CWE →
Monitor Heap-based Buffer Overflow Vulnerabilities
Get alerted when new Heap-based Buffer Overflow CVEs affect your infrastructure.
Start Monitoring Free