CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,315 vulnerabilities with CWE-122
CVE-2026-22027 MEDIUM
CryptoLib < 1.4.3 - Heap-based Buffer Overflow in MariaDB SA Interface
CVSS 6.0
CVE-2026-21682 HIGH
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccXmlArrayType::ParseText()
CVSS 8.8
CVE-2026-21678 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in IccTagXml()
CVSS 7.8
CVE-2026-21504 MEDIUM
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in ToneMap Parser
CVSS 6.6
CVE-2026-21494 MEDIUM
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagLut8::Validate()
CVSS 6.1
CVE-2026-21491 MEDIUM
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagTextDescription
CVSS 6.1
CVE-2026-21490 MEDIUM
iccDEV < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagLut16::Validate()
CVSS 6.1
CVE-2026-21488 MEDIUM
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccTagText::Read
CVSS 6.1
CVE-2026-21676 HIGH
iccDEV < 2.3.1.1 - Heap-based Buffer Overflow in CIccMBB::Validate
CVSS 8.8
CVE-2026-21486 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccSparseMatrix
CVSS 7.8
CVE-2025-55661 MEDIUM
GPAC MP4Box 2.4 - Heap-based Buffer Overflow in Opus Audio Stream Parser
CVSS 5.5
CVE-2025-55652 MEDIUM
GPAC MP4Box 2.4 - Heap-based Buffer Overflow in gf_isom_vp_config_new
CVSS 5.5
CVE-2025-55648 MEDIUM
GPAC MP4Box 2.4 - Denial of Service via Crafted MP4 File
CVSS 5.5
CVE-2025-55645 MEDIUM
GPAC MP4Box 2.4 - Heap-based Buffer Overflow in gf_cenc_set_pssh Function
CVSS 5.5
CVE-2025-55664 MEDIUM
GPAC MP4Box 2.4 - Heap-based Buffer Overflow in m2tsdmx_send_packet
CVSS 5.5
CVE-2025-70103 HIGH
libjxl 0.12.0 - Heap Buffer Overflow via Crafted PBM Images in DecodeImagePNM
CVSS 7.3
CVE-2025-62624 HIGH
ESXi 8.x And ESXi 9.x Hosts Using AMD-Pensando Dpu Products - Heap-based Buffer Overflow
CVE-2025-12659 HIGH
Heap-based buffer overflow in Siemens Simcenter Femap
CVSS 7.8
CVE-2025-70067 CRITICAL
Assimp <= 6.0.2 - Heap-based Buffer Overflow in FBX Importer
CVSS 9.8
CVE-2025-10685 HIGH
HTTP POST with specific higher content length leads into heap corruption
CVE-2025-61154 MEDIUM
LibreDWG v0.13.3.7571-0.13.3.7835 - DoS
CVSS 6.5
CVE-2025-69247 HIGH
free5GC go-upf <1.2.8 - Buffer Overflow
CVSS 7.5
CVE-2025-14905 HIGH
389-ds-base - Memory Corruption
CVSS 7.2
CVE-2025-70122 HIGH
free5gc v4.0.1 - Denial of Service via PFCP Session Modification Request
CVSS 7.5
CVE-2025-67433 HIGH
Open TFTP Server MultiThreaded <1.7 - DoS
CVSS 7.5
Details
Vulnerabilities 2,315
Exploit Likelihood High