CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 26 of 66
- CVE-2025-49691HIGHCVSS 8.0EG 8.02025-07-08
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2023-28905HIGHCVSS 8.0EG 8.02025-06-28
A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM par…
- CVE-2025-27487HIGHCVSS 8.0EG 8.02025-04-08
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
- CVE-2024-46461HIGHCVSS 8.0EG 8.02024-09-25
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger e…
- CVE-2024-37987HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37977HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-30077HIGHCVSS 8.0EG 8.02024-06-11
Windows OLE Remote Code Execution Vulnerability
- CVE-2024-30075HIGHCVSS 8.0EG 8.02024-06-11
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
- CVE-2024-30074HIGHCVSS 8.0EG 8.02024-06-11
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
- CVE-2023-50230HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required…
- CVE-2023-50229HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required…
- CVE-2023-51795HIGHCVSS 8.0EG 8.02024-04-19
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
- CVE-2023-50009HIGHCVSS 8.0EG 8.02024-04-19
FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
- CVE-2023-49501HIGHCVSS 8.0EG 8.02024-04-19
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
- CVE-2023-49528HIGHCVSS 8.0EG 8.02024-04-12
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
- CVE-2023-36425HIGHCVSS 8.0EG 8.02023-11-14
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
- CVE-2022-39852HIGHCVSS 8.0EG 8.02022-10-07
A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.
- CVE-2021-3968HIGHCVSS 8.0EG 8.02021-11-19
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-44708HIGHCVSS 7.8EG 8.02022-01-14
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary co…
- CVE-2019-9502HIGHCVSS 7.9EG 7.92020-02-03
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending s…
- CVE-2019-9501HIGHCVSS 7.9EG 7.92020-02-03
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, b…
- CVE-2020-6007HIGHCVSS 7.9EG 7.92020-01-23
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
- CVE-2026-103010HIGHCVSS 7.8EG 7.82026-10-08
Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to …
- CVE-2026-92368HIGHCVSS 7.8EG 7.82026-09-29
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can…
- CVE-2026-86926HIGHCVSS 7.8EG 7.82026-09-23
A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnera…
- CVE-2026-75649HIGHCVSS 7.8EG 7.82026-09-22
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious …
- CVE-2026-75665HIGHCVSS 7.8EG 7.82026-09-22
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious …
- CVE-2026-61714HIGHCVSS 7.8EG 7.82026-09-18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap a…
- CVE-2026-46655HIGHCVSS 7.8EG 7.82026-09-18
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].f…
- CVE-2026-63422HIGHCVSS 7.8EG 7.82026-09-18
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of …
- CVE-2026-81474HIGHCVSS 7.8EG 7.82026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privil…
- CVE-2026-55323HIGHCVSS 7.8EG 7.82026-09-15
In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…
- CVE-2026-19781HIGHCVSS 7.8EG 7.82026-09-15
Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction i…
- CVE-2026-90556HIGHCVSS 7.8EG 7.82026-09-12
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that…
- CVE-2026-79591HIGHCVSS 7.8EG 7.82026-09-10
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
- CVE-2026-81992HIGHCVSS 7.8EG 7.82026-09-08
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma…
- CVE-2026-82006HIGHCVSS 7.8EG 7.82026-09-08
Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- CVE-2026-58820HIGHCVSS 7.8EG 7.82026-09-08
In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.
- CVE-2026-55294HIGHCVSS 7.8EG 7.82026-09-08
In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…
- CVE-2026-49932HIGHCVSS 7.8EG 7.82026-09-08
In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2026-45531HIGHCVSS 7.8EG 7.82026-09-08
In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2026-45515HIGHCVSS 7.8EG 7.82026-09-08
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges neede…
- CVE-2026-84000HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
- CVE-2026-83995HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-83985HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83983HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83987HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83980HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83982HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-83978HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →