CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,135 vulnerabilities with CWE-122
CVE-2025-27171 HIGH
InDesign Desktop <ID20.1,ID19.5.2 - RCE
CVSS 7.8
CVE-2025-24453 HIGH
Adobe Indesign < 19.5.3 - Out-of-Bounds Write
CVSS 7.8
CVE-2025-24443 HIGH
Adobe Substance 3D Sampler < 5.0 - Out-of-Bounds Write
CVSS 7.8
CVE-2025-24439 HIGH
Adobe Substance 3D Sampler < 5.0 - Out-of-Bounds Write
CVSS 7.8
CVE-2025-26634 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20915 - Heap Buffer Overflow
CVSS 7.5
CVE-2025-24995 HIGH
Kernel Streaming WOW Thunk Service Driver - Privilege Escalation
CVSS 7.8
CVE-2025-24993 HIGH KEV
Windows NTFS - Buffer Overflow
CVSS 7.8
CVE-2025-24985 HIGH KEV
Windows Fast FAT Driver - Code Injection
CVSS 7.8
CVE-2025-24067 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-24066 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-24057 HIGH
Microsoft 365 Apps - Heap Buffer Overflow
CVSS 7.8
CVE-2025-24056 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Heap Buffer Overflow
CVSS 8.8
CVE-2025-24051 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Heap Buffer Overflow
CVSS 8.8
CVE-2025-24050 HIGH
Microsoft Windows 10 1607 < 10.0.14393.7876 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-24048 HIGH
Microsoft Windows 10 1607 < 10.0.14393.7876 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-21180 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-21169 HIGH
Adobe Substance 3D Designer < 14.1.1 - Out-of-Bounds Write
CVSS 7.8
CVE-2025-2153 MEDIUM
HDF5 1.14.6 - Buffer Overflow
CVSS 5.0
CVE-2025-2152 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Buffer Overflow
CVSS 6.3
CVE-2025-1943 HIGH
Firefox <136 - Memory Corruption
CVSS 8.2
CVE-2025-1788 MEDIUM
rizinorg rizin <0.8.0 - Buffer Overflow
CVSS 5.3
CVE-2025-22881 HIGH
Deltaww Cncsoft-g2 < 2.1.0.20 - Heap Buffer Overflow
CVSS 7.8
CVE-2025-1538 HIGH
Dlink Dap-1320 Firmware - Out-of-Bounds Write
CVSS 8.8
CVE-2025-27091 HIGH
OpenH264 - Heap Overflow
CVSS 7.5
CVE-2025-1426 HIGH
Google Chrome < 133.0.6943.126 - Heap Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,135
Exploit Likelihood High