CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-47162 HIGH
Microsoft 365 Apps and Office - Heap-based Buffer Overflow
CVSS 8.4
CVE-2025-33066 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Remote Code Execution via RRAS Heap Overflow
CVSS 8.8
CVE-2025-33064 HIGH
Windows 10/11, Server 2008 - Authenticated RCE via RRAS Heap Overflow
CVSS 8.8
CVE-2025-32718 HIGH
Windows 10/11, Server 2012-2016 SMB Authenticated Privilege Escalation via Integer Overflow
CVSS 7.8
CVE-2025-32713 HIGH
Windows Common Log File System Driver - Authenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-30317 HIGH
InDesign Desktop <ID20.2,ID19.5.3 - Buffer Overflow
CVSS 7.8
CVE-2025-5915 MEDIUM
libarchive < 3.8.0 - Heap-based Buffer Overflow via LZSS Decompression
CVSS 6.6
CVE-2025-5750 HIGH
WOLFBOX Level 2 EV Charger Firmware - Heap-based Buffer Overflow via tuya_svc_devos_activate_result_parse
CVSS 8.8
CVE-2025-48910 MEDIUM
HarmonyOS - Heap-based Buffer Overflow in DFile Module
CVSS 5.5
CVE-2025-1051 HIGH
Sonos Era 300 Firmware - Unauthenticated Heap-based Buffer Overflow via ALAC Data Processing
CVSS 8.8
CVE-2025-48990 HIGH
nekernel 0.0.2 - Heap-based Buffer Overflow in rt_copy_memory
CVE-2025-20672 CRITICAL
MediaTek MT7902/MT7921/MT7922/MT7925/MT7927 Firmware < 3.6 - Heap-based Buffer Overflow in Bluetooth Driver
CVSS 9.8
CVE-2025-44905 HIGH
HDF5 1.14.6 - Heap-based Buffer Overflow via H5Z__filter_scaleoffset Function
CVSS 8.8
CVE-2025-44904 HIGH
HDF5 1.14.6 - Heap-based Buffer Overflow via H5VM_memcpyvv Function
CVSS 8.8
CVE-2025-48797 HIGH
GIMP - Heap Buffer Overflow
CVSS 7.3
CVE-2025-23123 CRITICAL
UniFi Protect Cameras <4.75.43 - RCE
CVSS 10.0
CVE-2025-40906 CRITICAL
BSON::XS < 0.8.4 - Use of Unmaintained Third Party Components
CVSS 9.8
CVE-2025-40907 MEDIUM
FCGI 0.44-0.82 - Integer Overflow via Crafted nameLen or valueLen in IPC Socket Data
CVSS 5.3
CVE-2025-2900 HIGH
IBM Semeru Runtime <21.0.6.0 - DoS
CVSS 7.5
CVE-2025-47436 CRITICAL
Apache ORC < 1.8.9, 1.9.0-1.9.5, 2.0.0-2.0.4, 2.1.0-2.1.1 - Heap-based Buffer Overflow in C++ LZO Decompression
CVSS 9.8
CVE-2025-30330 HIGH
Illustrator <29.3,28.7.5 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-30388 HIGH
Microsoft Windows Win32K - GRFX Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-30376 HIGH
Microsoft Office Excel - Buffer Overflow
CVSS 7.8
CVE-2025-29979 HIGH
Microsoft Office Excel - Buffer Overflow
CVSS 7.8
CVE-2025-29967 HIGH
Microsoft Windows Remote Desktop Gateway Service - Heap-based Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,325
Exploit Likelihood High