CWE-122
High likelihoodHeap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
2,325 vulnerabilities with CWE-122
CVE-2025-29966
HIGH
Windows Remote Desktop - Buffer Overflow
CVSS 8.8
CVE-2025-29964
HIGH
Microsoft Windows Media - Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-29963
HIGH
Microsoft Windows Media - Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-29962
HIGH
Microsoft Windows Media - Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-24063
HIGH
Windows 10 1507-22H2 and Windows 11 22H2 - Authenticated Privilege Escalation via Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-47815
MEDIUM
GNU PSPP < 2.0.1 - Heap-based Buffer Overflow in zip-reader.c
CVSS 4.5
CVE-2025-47814
MEDIUM
GNU PSPP < 2.0.1 - Heap-based Buffer Overflow in zip-reader.c
CVSS 4.5
CVE-2025-3713
HIGH
LCD KVM over IP Switch <2.2.215 - Buffer Overflow
CVSS 7.5
CVE-2025-3712
HIGH
LCD KVM over IP Switch <2.2.215 - Buffer Overflow
CVSS 7.5
CVE-2025-1252
HIGH
RTI Connext Professional - Buffer Overflow
CVSS 7.1
CVE-2025-31177
MEDIUM
gnuplot - Heap-based Buffer Overflow in utf8_copy_one
CVSS 5.5
CVE-2025-32401
MEDIUM
RT-Labs P-Net < 1.0.2 - Heap-based Buffer Overflow via Malicious RPC Packet
CVSS 4.8
CVE-2025-32400
HIGH
RT-Labs P-Net < 1.0.2 - Heap-based Buffer Overflow via Malicious RPC Packet
CVSS 7.5
CVE-2025-32397
HIGH
RT-Labs P-Net < 1.0.2 - Heap-based Buffer Overflow via Malicious RPC Packet
CVSS 7.5
CVE-2025-32396
HIGH
RT-Labs P-Net < 1.0.2 - Heap-based Buffer Overflow via Malicious RPC Packet
CVSS 7.5
CVE-2025-4355
HIGH
Tenda DAP-1520 1.10B04_BETA02 - Heap-Based Buffer Overflow in set_ws_action
CVSS 8.8
CVE-2025-4096
HIGH
Google Chrome < 136.0.7103.59 - Heap-based Buffer Overflow via Crafted HTML Page
CVSS 8.8
CVE-2025-46333
HIGH
z2d <0.6.1 - Buffer Overflow
CVE-2025-1049
HIGH
Sonos S1 < 57.22-61162 and S2 < 83.1-61240 - Unauthenticated Heap-based Buffer Overflow via ID3 Data Processing
CVSS 8.8
CVE-2025-1045
HIGH
Luxion KeyShot < 2025.1 - Remote Code Execution via KSP File Parsing Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-3791
MEDIUM
symisc UnQLite <957c377cb691a4f617db9aba5cc46d90425071e2 - Buffer O...
CVSS 5.3
CVE-2025-3619
HIGH
Google Chrome < 135.0.7049.95 - Heap-based Buffer Overflow in Codecs via Crafted HTML Page
CVSS 8.8
CVE-2025-2497
HIGH
Autodesk Revit 2024-2024.3.2 - Stack-Based Buffer Overflow via Malicious DWG File
CVSS 7.8
CVE-2025-1656
HIGH
Autodesk Revit 2023-2023.1.7 - Heap-Based Buffer Overflow via Malicious PDF Import
CVSS 7.8
CVE-2025-1275
HIGH
Autodesk AutoCAD Mechanical < 2023.1.7 - Heap-Based Buffer Overflow via Malicious JPG File
CVSS 7.8
Details
Vulnerabilities
2,325
Exploit Likelihood
High