CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,317 vulnerabilities with CWE-122
CVE-2025-5517 MEDIUM
ABB Terra AC <1.8.32-1.8.2 - Buffer Overflow
CVSS 6.8
CVE-2025-11947 MEDIUM
bftpd < 6.2 - Heap-Based Buffer Overflow in Configuration File Handler
CVSS 4.5
CVE-2025-61553 HIGH
BitVisor 108df6-480907 - Heap-based Buffer Overflow in VirtIO Network Device Emulation
CVSS 8.2
CVE-2025-54278 MEDIUM
Adobe Bridge < 14.1.9 - Heap-based Buffer Overflow via Malicious File
CVSS 5.5
CVE-2025-54268 HIGH
Adobe Bridge < 14.1.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-61804 HIGH
Adobe Animate < 23.0.15 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-54282 HIGH
Adobe Framemaker < 2020.10 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-59295 HIGH
Windows 10 1507-22H2, Windows 11 22H2-25H2, Windows Server 2008 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-59275 HIGH
Windows Authentication Methods - Privilege Escalation
CVSS 7.8
CVE-2025-59255 HIGH
Windows DWM Core Library - Authenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-59254 HIGH
Windows 10/11, Server 2016 - Privilege Escalation via Heap Overflow
CVSS 7.8
CVE-2025-59242 HIGH
Windows 10/11, Server 2008 - Privilege Escalation via AFD Heap Overflow
CVSS 7.8
CVE-2025-59191 HIGH
Windows 10/11, Server 2019/2022/2025 - Privilege Escalation via Heap Overflow in Connected Devices Platform
CVSS 7.8
CVE-2025-58725 HIGH
Windows 10 1507-22H2, Windows 11 22H2-25H2, Windows Server 2008 - Authenticated Heap-based Buffer Overflow
CVSS 7.0
CVE-2025-58722 HIGH
Windows DWM - Authenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-55697 HIGH
Windows Server 2022 23H2/2025 Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-57740 HIGH
FortiOS < 7.2.11, FortiPAM < 1.4.3, FortiProxy < 7.4.4 - Heap-based Buffer Overflow via RDP Bookmark
CVSS 7.5
CVE-2025-22258 MEDIUM
Fortinet <7.6.2 - Privilege Escalation
CVSS 6.5
CVE-2025-20720 HIGH
MediaTek Software Development Kit - Heap-based Buffer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-20712 HIGH
MediaTek Software Development Kit < 8.3.1.1 - Heap-based Buffer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-11495 LOW
GNU Binutils 2.45 - Heap-Based Buffer Overflow in elf_x86_64_relocate_section
CVSS 3.3
CVE-2025-43912 MEDIUM
Dell PowerProtect Data Domain Unauthenticated Heap-based Buffer Overflow
CVSS 5.3
CVE-2025-11277 MEDIUM
Open Asset Import Library Assimp 6.0.2 - Buffer Overflow
CVSS 5.3
CVE-2025-11275 MEDIUM
Open Asset Import Library Assimp 6.0.2 - Buffer Overflow
CVSS 5.3
CVE-2025-10504 MEDIUM
ABB Terra AC <1.8.33 - Buffer Overflow
CVSS 6.1
Details
Vulnerabilities 2,317
Exploit Likelihood High