CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,315 vulnerabilities with CWE-122
CVE-2025-65085 CRITICAL
Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share <= 12.6.1204.216 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2025-64693 CRITICAL
MaLion/MaLionCloud - Buffer Overflow
CVSS 9.8
CVE-2025-65018 HIGH
libpng 1.6.0-1.6.50 - Heap-based Buffer Overflow in png_image_finish_read
CVSS 7.1
CVE-2025-62608 CRITICAL
MLX < 0.29.4 - Heap-based Buffer Overflow in NumPy File Parser
CVSS 9.1
CVE-2025-64524 LOW
cups-filters < 2.0.1 - Heap-based Buffer Overflow in rastertopclx Filter
CVSS 3.3
CVE-2025-46373 HIGH
FortiClientWindows 7.2.0-7.2.8 - Authenticated Heap-based Buffer Overflow via fortips_74.sys
CVSS 7.8
CVE-2025-63701 MEDIUM
Advantech TP-3250 - Memory Corruption
CVSS 6.8
CVE-2025-63927 MEDIUM
airpig2011 IEC104 < 2019-07-08 - Use-After-Free in Iec10x_Scheduled Function
CVSS 4.0
CVE-2025-61838 HIGH
Format Plugins <= 1.1.1 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-61837 HIGH
Format Plugins <= 1.1.1 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-62452 HIGH
Windows RRAS - Authenticated Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.0
CVE-2025-62220 HIGH
Windows Subsystem for Linux < 2.6.2 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-62201 HIGH
Microsoft Excel - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-61829 HIGH
Illustrator on iPad < 3.0.10 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61827 HIGH
Illustrator on iPad < 3.0.10 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61820 HIGH
Adobe Illustrator < 28.7.10 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61819 HIGH
Photoshop < 26.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-60724 CRITICAL
Microsoft Graphics Component - Buffer Overflow
CVSS 9.8
CVE-2025-60715 HIGH
Windows RRAS - Authenticated Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.0
CVE-2025-60714 HIGH
Microsoft Windows OLE - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-59504 HIGH
Azure Monitor Agent < 1.37.1 - Unauthenticated Heap-based Buffer Overflow
CVSS 7.3
CVE-2025-61832 HIGH
Adobe InDesign < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61824 HIGH
InDesign < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61816 HIGH
InCopy < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-62689 HIGH
GNU libmicrohttpd <= 1.0.2 - Denial of Service via NULL Pointer Dereference
CVSS 7.5
Details
Vulnerabilities 2,315
Exploit Likelihood High