CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-7067 LOW
HDF5 1.14.6 - Heap-Based Buffer Overflow in H5FS__sinfo_serialize_node_cb
CVSS 3.3
CVE-2025-45029 MEDIUM
WINSTAR WN572HP3 v230525 - Buffer Overflow
CVSS 6.5
CVE-2025-48379 HIGH
Pillow 11.2.0-11.2.9 - Heap-based Buffer Overflow in DDS Image Writing
CVSS 7.1
CVE-2025-6818 LOW
HDF5 1.14.6 - Heap-Based Buffer Overflow in H5O__chunk_protect
CVSS 3.3
CVE-2025-6816 LOW
HDF5 1.14.6 - Heap-Based Buffer Overflow in H5O__fsinfo_encode
CVSS 3.3
CVE-2025-6750 LOW
HDF5 1.14.6 - Heap-Based Buffer Overflow in H5O__mtime_new_encode
CVSS 3.3
CVE-2025-6660 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in GIF File Parser
CVSS 7.8
CVE-2025-5830 HIGH
Autel MaxiCharger AC Wallbox Commercial - RCE
CVSS 8.8
CVE-2025-6516 MEDIUM
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5F_addr_decode_len
CVSS 5.3
CVE-2025-6499 LOW
libucl < 0.9.2 - Heap-Based Buffer Overflow in ucl_parse_multiline_string
CVSS 3.3
CVE-2025-6494 LOW
Nokogiri - Heap-Based Buffer Overflow in hashmap_get_with_hash
CVSS 3.3
CVE-2025-6490 LOW
Nokogiri - Heap-Based Buffer Overflow in hashmap_set_with_hash
CVSS 3.3
CVE-2025-5479 HIGH
Sony XAV-AX8500 Firmware >=2.00.1 <3.02.00 - Remote Code Execution via Bluetooth AVCTP Protocol
CVSS 7.5
CVE-2025-5477 HIGH
Sony XAV-AX8500 Firmware >=2.00.01 <3.02.00 - Remote Code Execution via Bluetooth L2CAP Protocol
CVSS 7.5
CVE-2025-50054 MEDIUM
OpenVPN ovpn-dco-win <= 1.3.0 and <= 2.5.8 - Heap-based Buffer Overflow via Large Control Message
CVSS 5.5
CVE-2025-6270 MEDIUM
HDF5 < 2.0.0 - Heap-Based Buffer Overflow in H5FS__sect_find_node
CVSS 5.3
CVE-2025-6269 MEDIUM
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5C__reconstruct_cache_entry
CVSS 5.3
CVE-2025-20260 CRITICAL
ClamAV < 1.0.9 - Heap-based Buffer Overflow in PDF Scanner
CVSS 9.8
CVE-2025-49850 HIGH
LS Electric GMWin 4 >=4.18 - Heap-based Buffer Overflow in PRJ File Parser
CVE-2025-6120 MEDIUM
assimp < 5.4.3 - Heap-Based Buffer Overflow in read_meshes Function
CVSS 5.3
CVE-2025-47868 CRITICAL
Apache NuttX 6.9-12.9.0 - Heap-based Buffer Overflow in BDF-Converter Font Utility
CVSS 9.8
CVE-2025-32717 HIGH
Microsoft 365 Apps - Heap-based Buffer Overflow
CVSS 8.4
CVE-2025-47107 HIGH
InCopy < 19.5.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-47174 HIGH
Microsoft 365 Apps and Office Long Term Servicing Channel - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-47169 HIGH
Microsoft 365 Apps and Office - Heap-based Buffer Overflow
CVSS 7.8
Details
Vulnerabilities 2,325
Exploit Likelihood High