CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not re...Show more |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
1Nhi 1Health Insurance Web Service Component Jun 17, 2026 Jun 20, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memor...Show more |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Jun 19, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...Show more |
Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...Show more |
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat...Show more |
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat...Show more |
Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0. |
The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code |
2Debian Signalwire2Debian Linux Sofia SipJun 17, 2026 May 31, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 May 31, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
TensorFlow is an open source platform for machine learning. In version 2.8.0, the `TensorKey` hash function used total estimated `AllocatedBytes()`, which (a) is an estimate per tensor, and (b) is a very poor hash functi...Show more |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 May 11, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a heap-based buffer overflow vulnerability due to insecure handling of a crafted .pdf file,...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 May 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution |
5Apple DebianFedoraproject+2 more6Debian Linux FedoraHci Management Node+3 moreJun 17, 2026 May 8, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution |
All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code. |