CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-7207 LOW
mruby < 3.4.0 - Heap-Based Buffer Overflow in nregs Handler
CVSS 3.3
CVE-2025-47131 HIGH
Adobe Framemaker < 2020.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47125 HIGH
Adobe Framemaker < 2020.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47123 HIGH
Adobe Framemaker < 2020.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47122 HIGH
Adobe Framemaker < 2020.9 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47099 HIGH
Adobe InCopy < 19.5.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47134 HIGH
Adobe InDesign < 19.5.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47103 HIGH
InDesign < 19.5.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-43591 HIGH
InDesign < 19.5.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-43582 HIGH
Substance3D Viewer < 0.25 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-49753 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 8.8
CVE-2025-49744 HIGH
Windows 10/11, Server 2016-2019 Local Privilege Escalation via Heap Overflow
CVSS 7.0
CVE-2025-49742 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Local Code Execution via Integer Overflow
CVSS 7.8
CVE-2025-49732 HIGH
Windows 10/11, Server 2008 - Privilege Escalation via Heap Overflow in Graphics
CVSS 7.8
CVE-2025-49730 HIGH
Windows 10/11, Server 2008 - Privilege Escalation via QoS Scheduler TOCTOU
CVSS 7.8
CVE-2025-49729 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 8.8
CVE-2025-49727 HIGH
Windows Win32K < 10.0.26100.4652 Authenticated Privilege Escalation via Heap-based Buffer Overflow
CVSS 7.0
CVE-2025-49721 HIGH
Windows Fast FAT Driver - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-49717 HIGH
SQL Server 2019/2022 Authenticated RCE via Heap-based Buffer Overflow
CVSS 8.5
CVE-2025-49705 HIGH
Microsoft PowerPoint - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-49697 HIGH
Microsoft 365 Apps and Office - Heap-based Buffer Overflow
CVSS 8.4
CVE-2025-49696 HIGH
Microsoft 365 Apps and Office - Out-of-bounds Read
CVSS 8.4
CVE-2025-49691 HIGH
Windows 10/11, Server 2016-2019 - Remote Code Execution via Heap Overflow in Windows Media
CVSS 8.0
CVE-2025-49683 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Local Code Execution via VHDX Integer Overflow
CVSS 7.8
CVE-2025-49676 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 2,325
Exploit Likelihood High