CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,325 vulnerabilities with CWE-122
CVE-2025-58447
CRITICAL
rAthena <commit 2f5248b - Buffer Overflow
CVSS 9.8
CVE-2025-54244
HIGH
Substance3D Viewer < 0.25.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-54910
HIGH
Microsoft 365 Apps and Office - Heap-based Buffer Overflow
CVSS 8.4
CVE-2025-54907
HIGH
Microsoft Office Visio - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-54900
HIGH
Microsoft Excel - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-54894
HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Local Privilege Escalation via LSASS Heap Overflow
CVSS 7.8
CVE-2025-54113
HIGH
Windows Server 2008/2012/2016/2019/2022/2025 <10.0.26100.6508 - RCE via RRAS Heap Overflow
CVSS 8.8
CVE-2025-54091
HIGH
Windows Hyper-V - Authenticated Privilege Escalation via Integer Overflow
CVSS 7.8
CVE-2025-9951
HIGH
FFmpeg < 8.0 - Heap-based Buffer Overflow via JPEG2000 Channel Definition Atom
CVE-2025-40930
HIGH
JSON::SIMD < 1.07 - Heap-based Buffer Overflow via Crafted JSON Parsing
CVSS 7.5
CVE-2025-40929
MEDIUM
Cpanel::JSON::XS <4.40 - Buffer Overflow
CVSS 5.6
CVE-2025-40928
HIGH
JSON::XS < 4.04 - Heap-based Buffer Overflow via Crafted JSON Parsing
CVSS 7.5
CVE-2025-36853
HIGH
msdia140.dll - Heap-based Buffer Overflow
CVSS 7.5
CVE-2025-57807
LOW
ImageMagick < 6.9.13-29 - Heap-Based Buffer Overflow via SeekBlob and WriteBlob Functions
CVSS 3.8
CVE-2025-32318
HIGH
Android Skia - Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-32325
HIGH
Android - Heap-based Buffer Overflow in Parcel.cpp appendFrom
CVSS 7.8
CVE-2025-26455
HIGH
Android - Heap-based Buffer Overflow in NdkMediaCodec.cpp
CVSS 7.8
CVE-2025-36907
HIGH
Android - Heap-based Buffer Overflow in draw_surface_image()
CVSS 7.3
CVE-2025-36906
HIGH
Android - Heap-based Buffer Overflow in ConvertReductionOp
CVSS 7.8
CVE-2025-36902
MEDIUM
Android - Heap-based Buffer Overflow in syna_cdev_ioctl_store_pid()
CVSS 6.7
CVE-2025-26416
CRITICAL
Android - Heap-based Buffer Overflow in SkBmpStandardCodec.cpp
CVSS 9.8
CVE-2025-8302
HIGH
Realtek Wi-Fi USB Driver < 1030.52.0325.2025 - Heap-based Buffer Overflow in N6CSet_DOT11_CIPHER_DEFAULT_KEY
CVSS 8.8
CVE-2025-8301
HIGH
Realtek Wi-Fi USB Driver < 1030.52.0325.2025 - Local Privilege Escalation via Heap Overflow
CVSS 7.8
CVE-2025-8300
HIGH
Realtek Wi-Fi USB Driver < 1030.52.0325.2025 - Local Privilege Escalation via Heap Overflow
CVSS 8.8
CVE-2025-8299
HIGH
Realtek Wi-Fi USB Driver < 1030.52.0325.2025 - Heap-based Buffer Overflow in MgntActSet_TEREDO_SET_RS_PACKET
CVSS 8.8
Details
Vulnerabilities
2,325
Exploit Likelihood
High