CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 21 of 66
- CVE-2016-9581HIGHCVSS 3.3EG 8.82018-08-01
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.
- CVE-2026-6210HIGHCVSS 8.7EG 8.72026-05-06
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* with…
- CVE-2026-97152HIGHCVSS 8.6EG 8.62026-09-24
Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
- CVE-2025-54878HIGHCVSS 8.6EG 8.62025-08-11
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap b…
- CVE-2025-48990HIGHCVSS 8.6EG 8.62025-06-02
NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at `dst[len]`. When `len` equals the size of the destination buffer (256…
- CVE-2024-2011HIGHCVSS 8.6EG 8.62024-06-11
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit sec…
- CVE-2024-34199HIGHCVSS 8.6EG 8.62024-05-14
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.
- CVE-2024-20259HIGHCVSS 8.6EG 8.62024-03-27
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerabili…
- CVE-2024-24577HIGHCVSS 8.6EG 8.62024-02-06
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corrupti…
- CVE-2022-2601HIGHCVSS 8.6EG 8.62022-12-14
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buff…
- CVE-2021-26603HIGHCVSS 8.6EG 8.62021-09-09
A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check.
- CVE-2021-21006HIGHCVSS 8.6EG 8.62021-01-13
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires…
- CVE-2017-16717HIGHCVSS 8.6EG 8.62017-12-20
A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI. The heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.
- CVE-2024-56406HIGHCVSS 8.4EG 8.62025-04-13
A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10. When there are non-ASCII bytes in the left-hand-side of th…
- CVE-2023-0210HIGHCVSS 7.5EG 8.62023-03-27
A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
- CVE-2024-20697HIGHCVSS 7.3EG 8.62024-01-09
Windows libarchive Remote Code Execution Vulnerability
- CVE-2026-87679HIGHCVSS 8.5EG 8.52026-10-08
When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boundary checks on the maximum allowable num…
- CVE-2026-106547HIGHCVSS 8.5EG 8.52026-10-06
A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are re…
- CVE-2025-49717HIGHCVSS 8.5EG 8.52025-07-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2024-45421HIGHCVSS 8.5EG 8.52025-02-25
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
- CVE-2024-39825HIGHCVSS 8.5EG 8.52024-08-14
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
- CVE-2022-39260HIGHCVSS 8.5EG 8.52022-10-19
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5,…
- CVE-2022-20737HIGHCVSS 8.5EG 8.52022-05-03
A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of serv…
- CVE-2020-15196HIGHCVSS 8.5EG 8.52020-09-25
In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has the same shape as the data. The check exists for `DenseCountSparseOutput`, where both ten…
- CVE-2020-15195HIGHCVSS 8.5EG 8.52020-09-25
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an index outside of bounds of `grad_values…
- CVE-2026-55999HIGHCVSS 7.8EG 8.52026-07-08
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
- CVE-2023-44442HIGHCVSS 7.8EG 8.52024-05-03
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vuln…
- CVE-2026-58679HIGHCVSS 8.4EG 8.42026-09-15
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-69638HIGHCVSS 8.4EG 8.42026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-69479HIGHCVSS 8.4EG 8.42026-09-08
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-20502HIGHCVSS 8.4EG 8.42026-09-07
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2026-20501HIGHCVSS 8.4EG 8.42026-09-07
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2026-69242HIGHCVSS 8.4EG 8.42026-08-20
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflo…
- CVE-2026-56189HIGHCVSS 8.4EG 8.42026-07-14
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
- CVE-2026-54122HIGHCVSS 8.4EG 8.42026-07-14
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
- CVE-2026-47635HIGHCVSS 8.4EG 8.42026-06-09
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-40364HIGHCVSS 8.4EG 8.42026-05-12
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-40363HIGHCVSS 8.4EG 8.42026-05-12
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-4892HIGHCVSS 8.4EG 8.42026-05-11
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
- CVE-2026-40706HIGHCVSS 8.4EG 8.42026-04-21
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflo…
- CVE-2026-32221HIGHCVSS 8.4EG 8.42026-04-14
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
- CVE-2025-50360HIGHCVSS 8.4EG 8.42025-12-03
A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper source file(.pr) could lead to arbitrary code execution or Denial of Service.
- CVE-2025-54910HIGHCVSS 8.4EG 8.42025-09-09
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49697HIGHCVSS 8.4EG 8.42025-07-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49696HIGHCVSS 8.4EG 8.42025-07-08
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49850HIGHCVSS 8.4EG 8.42025-06-17
A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, s…
- CVE-2025-32717HIGHCVSS 8.4EG 8.42025-06-11
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-47162HIGHCVSS 8.4EG 8.42025-06-10
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-0755HIGHCVSS 8.4EG 8.42025-03-18
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting …
- CVE-2024-45679HIGHCVSS 8.4EG 8.42024-09-18
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →