CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,563 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 8 of 52
- CVE-2021-43305HIGHCVSS 8.8EG 8.82022-03-14
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(…
- CVE-2021-44000HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visu…
- CVE-2021-44442HIGHCVSS 7.8EG 7.82021-12-14
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specia…
- CVE-2021-44445HIGHCVSS 7.8EG 7.82021-12-14
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specia…
- CVE-2021-44708HIGHCVSS 7.8EG 8.02022-01-14
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary co…
- CVE-2021-44709HIGHCVSS 7.8EG 7.82022-01-14
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary co…
- CVE-2021-45918HIGHCVSS 7.5EG 7.52022-06-20
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved …
- CVE-2021-45956CRITICALCVSS 9.8EG 9.82022-01-01
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowle…
- CVE-2021-46577HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46603HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46605HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46606HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46647HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46648HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
- CVE-2021-46653HIGHCVSS 7.8EG 7.82022-02-18
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2022-0080CRITICALCVSS 9.8EG 9.82022-01-02
mruby is vulnerable to Heap-based Buffer Overflow
- CVE-2022-0158LOWCVSS 3.3EG 3.32022-01-10
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2022-0213MEDIUMCVSS 6.6EG 6.62022-01-14
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2022-0261HIGHCVSS 7.8EG 7.82022-01-18
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0318CRITICALCVSS 9.8EG 9.82022-01-21
Heap-based Buffer Overflow in vim/vim prior to 8.2.
- CVE-2022-0359HIGHCVSS 7.8EG 7.82022-01-26
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0361HIGHCVSS 7.8EG 7.82022-01-26
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0392HIGHCVSS 7.8EG 7.82022-01-28
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
- CVE-2022-0407HIGHCVSS 7.8EG 7.82022-01-30
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0417HIGHCVSS 7.8EG 7.82022-02-01
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
- CVE-2022-0518HIGHCVSS 7.1EG 7.12022-02-08
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
- CVE-2022-0570CRITICALCVSS 9.8EG 9.82022-02-14
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
- CVE-2022-0572HIGHCVSS 7.8EG 7.82022-02-14
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-0631CRITICALCVSS 9.8EG 9.82022-02-18
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
- CVE-2022-0676HIGHCVSS 7.8EG 7.82022-02-22
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
- CVE-2022-0713HIGHCVSS 7.1EG 7.12022-02-22
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
- CVE-2022-0714MEDIUMCVSS 5.5EG 5.52022-02-22
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
- CVE-2022-0943HIGHCVSS 7.8EG 7.82022-03-14
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
- CVE-2022-1052MEDIUMCVSS 5.5EG 5.52022-03-24
Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.
- CVE-2022-1061HIGHCVSS 7.5EG 7.52022-03-24
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.
- CVE-2022-1160HIGHCVSS 7.8EG 7.82022-03-30
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
- CVE-2022-1240HIGHCVSS 7.8EG 7.82022-04-06
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I thi…
- CVE-2022-1244MEDIUMCVSS 5.5EG 5.52022-04-05
heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.
- CVE-2022-1253CRITICALCVSS 9.8EG 9.82022-04-06
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
- CVE-2022-1286CRITICALCVSS 9.8EG 9.82022-04-10
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- CVE-2022-1381HIGHCVSS 7.8EG 7.82022-04-18
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- CVE-2022-1383MEDIUMCVSS 6.1EG 6.12022-04-18
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memor…
- CVE-2022-1437HIGHCVSS 7.1EG 7.12022-04-22
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memor…
- CVE-2022-1619HIGHCVSS 7.8EG 7.82022-05-08
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
- CVE-2022-1621HIGHCVSS 7.8EG 7.82022-05-10
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- CVE-2022-1714HIGHCVSS 7.1EG 7.12022-05-13
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locati…
- CVE-2022-1733HIGHCVSS 7.8EG 7.82022-05-17
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
- CVE-2022-1886HIGHCVSS 7.8EG 7.82022-05-26
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- CVE-2022-1890HIGHCVSS 6.7EG 7.82023-01-26
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- CVE-2022-1891HIGHCVSS 6.7EG 7.82023-01-26
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →