CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,315 vulnerabilities with CWE-122
CVE-2025-70299 MEDIUM
GPAC 2.4.0 - Denial of Service via Crafted AVI File
CVSS 6.5
CVE-2025-70310 MEDIUM
GPAC 2.4.0 - Denial of Service via Crafted OGG File in vorbis_to_intern()
CVSS 5.5
CVE-2025-25249 HIGH
Fortinet FortiOS <7.6.3 - Buffer Overflow
CVSS 8.1
CVE-2025-46643 LOW
Dell PowerProtect Data Domain - Buffer Overflow
CVSS 2.3
CVE-2025-67268 CRITICAL
gpsd < 3.27.1 - Heap-based Buffer Overflow in NMEA2000 PGN 129540 Packet Handling
CVSS 9.8
CVE-2025-15279 HIGH
FontForge - Heap-based Buffer Overflow in BMP File Parser
CVSS 7.8
CVE-2025-15277 HIGH
FontForge - Heap-based Buffer Overflow in SGI File Parser
CVSS 7.8
CVE-2025-15275 HIGH
FontForge - Heap-based Buffer Overflow in SFD File Parser
CVSS 8.8
CVE-2025-15274 HIGH
FontForge - Heap-based Buffer Overflow via SFD File Parsing
CVSS 8.8
CVE-2025-15272 HIGH
FontForge - Heap-based Buffer Overflow in SFD File Parsing
CVSS 8.8
CVE-2025-11961 LOW
libpcap < 1.10.6 - Heap-based Buffer Overflow in pcap_ether_aton()
CVSS 1.9
CVE-2025-50343 CRITICAL
matio 1.5.28 - Heap-based Buffer Overflow in Mat_VarCreateStruct
CVSS 9.8
CVE-2025-15247 HIGH
gmg137 snap7-rs - Heap-Based Buffer Overflow in S7Client::download Function
CVSS 7.3
CVE-2025-15234 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via formSetRemoteInternetLanInfo
CVSS 8.8
CVE-2025-15233 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via formSetAdInfoDetails
CVSS 8.8
CVE-2025-15230 HIGH
Tenda M3 1.0.0.13(4903) - Heap-based Buffer Overflow via qvlan_truck_port Parameter
CVSS 8.8
CVE-2025-66869 HIGH
libming 0.4.8 - Heap-based Buffer Overflow in strcat Function
CVSS 7.5
CVE-2025-66862 HIGH
BinUtils 2.26 - Heap-based Buffer Overflow in gnu_special Function via Crafted PE File
CVSS 7.5
CVE-2025-14425 HIGH
GIMP JP2 File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2025-12840 HIGH
OpenEXR EXR File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2025-12839 HIGH
Academy Software Foundation OpenEXR - RCE
CVSS 7.8
CVE-2025-12495 HIGH
OpenEXR < 3.4.3 - Remote Code Execution via EXR File Parsing Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-14935 HIGH
Unidata NetCDF-C - Heap-based Buffer Overflow in Dimension Name Parser
CVSS 7.8
CVE-2025-14958 MEDIUM
floooh sokol - Heap-Based Buffer Overflow in _sg_pipeline_common_init
CVSS 5.3
CVE-2025-14956 MEDIUM
WebAssembly Binaryen < 125 - Heap-Based Buffer Overflow in WasmBinaryReader::readExport
CVSS 5.3
Details
Vulnerabilities 2,315
Exploit Likelihood High