CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-8843 MEDIUM
NASM Netwide Assembler 2.17rc0 - Heap-Based Buffer Overflow in macho_no_dead_strip
CVSS 5.3
CVE-2025-54951 CRITICAL
ExecuTorch < 0.7.0 - Heap-based Buffer Overflow in Model Loading
CVSS 9.8
CVE-2025-54949 CRITICAL
ExecuTorch < 0.7.0 - Heap-based Buffer Overflow in Model Loading
CVSS 9.8
CVE-2025-3354 HIGH
IBM Tivoli Monitoring <6.3.0.7 - Buffer Overflow
CVSS 8.1
CVE-2025-3320 HIGH
IBM Tivoli Monitoring <6.3.0.7 - Buffer Overflow
CVSS 8.1
CVE-2025-23317 CRITICAL
NVIDIA Triton Inference Server < 25.07 - Remote Code Execution via HTTP Request
CVSS 9.1
CVE-2025-54630 MEDIUM
HarmonyOS - Denial of Service via DFA Module Data Length Verification
CVSS 6.8
CVE-2025-7033 HIGH
Rockwell Automation Arena < 16.20.10 - Heap-based Buffer Overflow via Custom File
CVSS 7.8
CVE-2025-7025 HIGH
Rockwell Automation Arena < 16.20.10 - Heap-based Buffer Overflow via Custom File
CVSS 7.8
CVE-2025-54574 CRITICAL
Squid < 6.4 - Heap-based Buffer Overflow via URN Processing
CVSS 9.3
CVE-2025-48071 HIGH
OpenEXR 3.3.0-3.3.2 - Heap-based Buffer Overflow via ZIPS-packed Deep Scan-line EXR Chunk Header
CVSS 7.8
CVE-2025-31280 HIGH
macOS < 15.6 - Heap-based Buffer Overflow via Maliciously Crafted File
CVSS 7.8
CVE-2025-5043 HIGH
Autodesk <version> - Buffer Overflow
CVSS 7.8
CVE-2025-8178 HIGH
Tenda AC10 16.03.10.13 - Heap-Based Buffer Overflow via device1D Argument
CVSS 8.8
CVE-2025-51089 MEDIUM
Tenda AC8V4 V16.03.34.06 - Buffer Overflow
CVSS 6.5
CVE-2025-40597 HIGH
SonicWall SMA 500v, SMA 210, SMA 410 Firmware < 10.2.2.1-90sv - Unauthenticated Heap-based Buffer Overflow
CVSS 7.5
CVE-2025-4657 MEDIUM
Lenovo Protection Driver <5.1.1110.4231 - Buffer Overflow
CVSS 6.7
CVE-2025-53816 HIGH
7-Zip < 25.0.0 - Heap-based Buffer Overflow in RAR5 Handler
CVSS 7.5
CVE-2025-24477 MEDIUM
FortiOS 7.2.4-7.2.12, 7.4.0-7.4.7, 7.6.0-7.6.2 - Heap-based Buffer Overflow via CLI Command
CVSS 4.2
CVE-2025-7545 MEDIUM
GNU Binutils <2.45 - Heap-based Buffer Overflow
CVSS 5.3
CVE-2025-53630 HIGH
llama.cpp - Heap-based Buffer Overflow in gguf_init_from_file_impl
CVE-2025-5040 HIGH
Autodesk Revit - Heap-Based Overflow
CVSS 7.8
CVE-2025-32990 MEDIUM
GnuTLS - Heap-based Buffer Overflow in Certtool Template Parsing
CVSS 6.5
CVE-2025-49604 MEDIUM
Realtek AmebaD <3.1.9 - Buffer Overflow
CVSS 5.4
CVE-2025-7208 MEDIUM
plan9port < 2025-03-29 - Heap-Based Buffer Overflow in x509.c edump Function
CVSS 5.5
Details
Vulnerabilities 2,325
Exploit Likelihood High