CWE-122 · 2,936 records
Heap-based Buffer Overflow
CVEs in this class
2,944 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-27997Weaponized | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,fortinet · fortiproxy · CWE-122 | Critical9.8 | KEV | 85.7% | Jun 13, 2023 |
91Now | CVE-2021-21017Weaponized | Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Executionadobe · acrobat · CWE-122 | High8.8 | KEV | 86.3% | Feb 11, 2021 |
85Now | CVE-2023-4911Weaponized | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | High7.8 | KEV | 81.4% | Oct 3, 2023 |
85Now | CVE-2024-38812Weaponized | Heap-overflow vulnerabilityvmware · cloud foundation · CWE-122 | Critical9.8 | KEV | 54.6% | Sep 17, 2024 |
78This week | CVE-2019-3568Weaponized | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a whatsapp · whatsapp · CWE-122 | Critical9.8 | KEV | 30.1% | May 14, 2019 |
76This week | CVE-2023-28252Weaponized | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 49.0% | Apr 11, 2023 |
70This week | CVE-2025-25249Weaponized | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1fortinet · fortios · CWE-122 | Critical9.8 | KEV | 3.9% | Jan 13, 2026 |
69This week | CVE-2024-49138Weaponized | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 26.2% | Dec 11, 2024 |
68This week | CVE-2026-94127Weaponized | BIG-IP APM OAuth vulnerabilityf5 · big-ip access policy manager · CWE-122 | Critical9.3 | KEV | 2.2% | Sep 22, 2026 |
66This week | CVE-2023-36036Weaponized | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 16.7% | Nov 14, 2023 |
64This week | CVE-2024-38077Proof of concept | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerabilitymicrosoft · windows server 2008 · CWE-122 | Critical9.8 | — | 84.2% | Jul 9, 2024 |
64This week | CVE-2023-23376Weaponized | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 10.9% | Feb 14, 2023 |
64This week | CVE-2025-21333Weaponized | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-122 | High7.8 | KEV | 10.0% | Jan 14, 2025 |
63This week | CVE-2024-30051Weaponized | Windows DWM Core Library Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 5.6% | May 14, 2024 |
62This week | CVE-2025-24985Weaponized | Windows Fast FAT File System Driver Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 3.8% | Mar 11, 2025 |
62This week | CVE-2026-85880Weaponized | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High7.8 | KEV | 3.6% | Sep 8, 2026 |
62This week | CVE-2025-24993Weaponized | Windows NTFS Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-122 | High7.8 | KEV | 2.2% | Mar 11, 2025 |
61This week | CVE-2022-35711No exploit | Adobe ColdFusion ODBC Server Heap-based Buffer Overflow Remote Code Execution Vulnerabilityadobe · coldfusion · CWE-122 | Critical9.8 | — | 73.5% | Oct 14, 2022 |
61This week | CVE-2024-12084Proof of concept | Rsync: heap buffer overflow in rsync due to improper checksum length handlingsamba · rsync · CWE-122 | Critical9.8 | — | 72.1% | Jan 15, 2025 |
61This week | CVE-2025-21418Weaponized | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High7.8 | KEV | 1.6% | Feb 11, 2025 |
59Plan | CVE-2021-26691No exploit | Apache HTTP Server mod_session response handling heap overflowapache · http server · CWE-122 | Critical9.8 | — | 68.3% | Jun 10, 2021 |
58Plan | CVE-2023-36824No exploit | Heap overflow in COMMAND GETKEYS and ACL evaluation in Redisredis · redis · CWE-122 | High8.8 | — | 77.4% | Jul 11, 2023 |
58Plan | CVE-2020-6146No exploit | An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.gonitro · nitro pro · CWE-122 | High8.8 | — | 76.1% | Sep 16, 2020 |
56Plan | CVE-2024-26256No exploit | Libarchive Remote Code Execution Vulnerabilitylibarchive · libarchive · CWE-122 | High7.8 | — | 84.8% | Apr 9, 2024 |
56Plan | CVE-2020-25681No exploit | A flaw was found in dnsmasq before version 2.83.thekelleys · dnsmasq · CWE-122 | High8.1 | — | 81.2% | Jan 20, 2021 |
- CVE-2023-2799795Now
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,
CriticalCVSS 9.8KEVWeaponizedEPSS 86%fortinet · fortiproxyJun 13, 2023
- CVE-2021-2101791Now
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
HighCVSS 8.8KEVWeaponizedEPSS 86%adobe · acrobatFeb 11, 2021
- CVE-2023-491185Now
Glibc: buffer overflow in ld.so leading to privilege escalation
HighCVSS 7.8KEVWeaponizedEPSS 81%gnu · glibcOct 3, 2023
- CVE-2024-3881285Now
Heap-overflow vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 55%vmware · cloud foundationSep 17, 2024
- CVE-2019-356878This week
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a
CriticalCVSS 9.8KEVWeaponizedEPSS 30%whatsapp · whatsappMay 14, 2019
- CVE-2023-2825276This week
Windows Common Log File System Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 49%microsoft · windows 10 1507Apr 11, 2023
- CVE-2025-2524970This week
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1
CriticalCVSS 9.8KEVWeaponizedEPSS 4%fortinet · fortiosJan 13, 2026
- CVE-2024-4913869This week
Windows Common Log File System Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 26%microsoft · windows 10 1507Dec 11, 2024
- CVE-2026-9412768This week
BIG-IP APM OAuth vulnerability
CriticalCVSS 9.3KEVWeaponizedEPSS 2%f5 · big-ip access policy managerSep 22, 2026
- CVE-2023-3603666This week
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 17%microsoft · windows 10 1507Nov 14, 2023
- CVE-2024-3807764This week
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 84%microsoft · windows server 2008Jul 9, 2024
- CVE-2023-2337664This week
Windows Common Log File System Driver Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 11%microsoft · windows 10 1507Feb 14, 2023
- CVE-2025-2133364This week
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 10%microsoft · windows 10 21h2Jan 14, 2025
- CVE-2024-3005163This week
Windows DWM Core Library Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 6%microsoft · windows 10 1507May 14, 2024
- CVE-2025-2498562This week
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 4%microsoft · windows 10 1507Mar 11, 2025
- CVE-2026-8588062This week
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 4%microsoft · windows 10 1607Sep 8, 2026
- CVE-2025-2499362This week
Windows NTFS Remote Code Execution Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 2%microsoft · windows 10 1507Mar 11, 2025
- CVE-2022-3571161This week
Adobe ColdFusion ODBC Server Heap-based Buffer Overflow Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 73%adobe · coldfusionOct 14, 2022
- CVE-2024-1208461This week
Rsync: heap buffer overflow in rsync due to improper checksum length handling
CriticalCVSS 9.8Proof of conceptEPSS 72%samba · rsyncJan 15, 2025
- CVE-2025-2141861This week
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 2%microsoft · windows 10 1607Feb 11, 2025
- CVE-2021-2669159Plan
Apache HTTP Server mod_session response handling heap overflow
CriticalCVSS 9.8No exploitEPSS 68%apache · http serverJun 10, 2021
- CVE-2023-3682458Plan
Heap overflow in COMMAND GETKEYS and ACL evaluation in Redis
HighCVSS 8.8No exploitEPSS 77%redis · redisJul 11, 2023
- CVE-2020-614658Plan
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.
HighCVSS 8.8No exploitEPSS 76%gonitro · nitro proSep 16, 2020
- CVE-2024-2625656Plan
Libarchive Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 85%libarchive · libarchiveApr 9, 2024
- CVE-2020-2568156Plan
A flaw was found in dnsmasq before version 2.83.
HighCVSS 8.1No exploitEPSS 81%thekelleys · dnsmasqJan 20, 2021