CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-49674 HIGH
Windows Server 2008-2025 RRAS Heap Overflow RCE
CVSS 8.8
CVE-2025-49673 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-49672 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 8.8
CVE-2025-49670 MEDIUM
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 6.5
CVE-2025-49669 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-49668 HIGH
Windows Server RRAS Heap Overflow Remote Code Execution
CVSS 8.8
CVE-2025-49666 HIGH
Windows Server 2016/2019/2022/2025 Authenticated RCE via Heap-based Buffer Overflow
CVSS 7.2
CVE-2025-49663 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-49657 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-48824 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-48805 HIGH
Microsoft MPEG-2 Video Extension - Buffer Overflow
CVSS 7.8
CVE-2025-47998 HIGH
Windows Server RRAS Heap Overflow RCE (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2025-47987 HIGH
Windows 10/11, Server 2008 - Authenticated Heap Overflow in CredSSP
CVSS 7.8
CVE-2025-47981 CRITICAL
Windows 10 1507-24H2 and Windows Server 2008-2012 - Heap-based Buffer Overflow in SPNEGO Extended Negotiation
CVSS 9.8
CVE-2025-50130 HIGH
FUJI ELECTRIC CO., LTD - Buffer Overflow
CVSS 7.8
CVE-2025-20686 HIGH
MediaTek Software Development Kit < 7.6.7.2 - Heap-based Buffer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-20685 HIGH
MediaTek Software Development Kit - Heap-based Buffer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-20680 CRITICAL
mediatek nbiot_sdk < 3.6 - Heap-based Buffer Overflow in Bluetooth Driver
CVSS 9.8
CVE-2025-53184 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-53183 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-53182 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-53181 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-53180 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-53179 MEDIUM
HarmonyOS - Null Pointer Dereference in PDF Preview Module
CVSS 6.5
CVE-2025-7069 LOW
HDF5 1.14.6 - Heap-Based Buffer Overflow in H5FS__sect_link_size
CVSS 3.3
Details
Vulnerabilities 2,325
Exploit Likelihood High