CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-34164 CRITICAL
NetSupport Manager <14.12.0000 - Buffer Overflow
CVE-2025-34523 CRITICAL
Arcserve UDP < 10.2 - Unauthenticated Heap-based Buffer Overflow via Network Input Handling
CVSS 9.8
CVE-2025-34522 CRITICAL
Arcserve UDP < 10.2 - Unauthenticated Heap-based Buffer Overflow
CVSS 9.8
CVE-2025-58050 CRITICAL
PCRE2 < 10.46 - Out-of-bounds Read via (*scs:...) and (*ACCEPT) Handling
CVSS 9.1
CVE-2025-57803 HIGH
ImageMagick < 6.9.13-28 - Integer Overflow in BMP Encoder
CVSS 7.5
CVE-2025-53085 HIGH
SAIL Image Decoding Library 0.9.8 - Heap-based Buffer Overflow in PSD RLE Decoding
CVSS 8.8
CVE-2025-50129 HIGH
SAIL Image Decoding Library v0.9.8 - RCE
CVSS 8.8
CVE-2025-35984 HIGH
SAIL Image Decoding Library 0.9.8 - Heap-based Buffer Overflow in PCX Image Decoding
CVSS 8.8
CVE-2025-54462 CRITICAL
libbiosig < 3.9.1 - Heap-based Buffer Overflow in Nex File Parsing
CVSS 9.8
CVE-2025-53853 CRITICAL
The Biosig Project libbiosig <3.9.0 - Buffer Overflow
CVSS 9.8
CVE-2025-53557 CRITICAL
The Biosig Project libbiosig <3.9.0 - Buffer Overflow
CVSS 9.8
CVE-2025-53511 CRITICAL
The Biosig Project libbiosig <3.9.0 - Buffer Overflow
CVSS 9.8
CVE-2025-48005 CRITICAL
libbiosig 3.9.0 and Master Branch - Heap-based Buffer Overflow in RHS2000 Parsing
CVSS 9.8
CVE-2025-52584 HIGH
Ashlar Argon, Cobalt, Cobalt Share, Lithium, Xenon < 12.6.1204.204 - Heap-based Buffer Overflow via XE File Parsing
CVSS 7.8
CVE-2025-46269 HIGH
Ashlar-Vellum Cobalt <12.6.1204.204 - Buffer Overflow
CVSS 7.8
CVE-2025-55286 HIGH
z2d v0.7.0 - Memory Corruption
CVE-2025-9019 LOW
tcpreplay 4.5.1 - Heap-Based Buffer Overflow in tcpprep mask_cidr6 Function
CVSS 3.1
CVE-2025-5942 MEDIUM
Netskope NS Client < unknown - Buffer Overflow
CVE-2025-50617 HIGH
Netis WF2880 v2.1.40207 - Buffer Overflow
CVSS 7.5
CVE-2025-55005 MEDIUM
ImageMagick <7.1.2-1 - Memory Corruption
CVSS 5.5
CVE-2025-55004 HIGH
ImageMagick <7.1.2-1 - Memory Corruption
CVSS 7.6
CVE-2025-8879 HIGH
Google Chrome < 139.0.7258.127 - Heap-based Buffer Overflow in libaom
CVSS 8.8
CVE-2025-54220 HIGH
InCopy < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-54219 HIGH
Adobe InCopy < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-54217 HIGH
InCopy < 19.5.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
Details
Vulnerabilities 2,325
Exploit Likelihood High