CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-1273 HIGH
Autodesk Revit 2023-2023.1.7 - Heap-Based Buffer Overflow via Malicious PDF Import
CVSS 7.8
CVE-2025-24797 CRITICAL
meshtastic_firmware < 2.6.2 - Unauthenticated Remote Code Execution via Invalid Protobuf Data
CVSS 9.4
CVE-2025-3277 CRITICAL
SQLite 3.44.0 to 3.49.1 concat_ws - Integer Overflow Code Execution
CVSS 9.8
CVE-2025-31344 HIGH
openEuler giflib <5.2.2 - Buffer Overflow
CVSS 7.3
CVE-2025-3549 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in MD3Importer ValidateSurfaceHeaderOffsets
CVSS 5.3
CVE-2025-3548 MEDIUM
assimp < 5.4.3 - Heap-Based Buffer Overflow in aiString::Set
CVSS 5.3
CVE-2025-3512 MEDIUM
Qt 6.8.0-6.8.4 - Buffer Overflow
CVE-2025-30644 HIGH
Juniper Junos Heap-based Buffer Overflow via DHCP Packet
CVSS 7.5
CVE-2025-30299 HIGH
Adobe Framemaker <2020.8, 2022.6 - RCE
CVSS 7.8
CVE-2025-30295 HIGH
Adobe Framemaker <2020.8, 2022.6 - RCE
CVSS 7.8
CVE-2025-29811 HIGH
Windows 11 22H2-24H2 and Windows Server 2022-2025 - Local Privilege Escalation via Mobile Broadband Input Validation
CVSS 7.8
CVE-2025-27752 HIGH
Microsoft 365 Apps and Office - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-27490 HIGH
Windows Bluetooth Service - Privilege Escalation
CVSS 7.8
CVE-2025-27487 HIGH
Remote Desktop Client - Buffer Overflow
CVSS 8.0
CVE-2025-27478 HIGH
Windows 10/11, Server 2008 - Local Privilege Escalation via Heap Overflow in LSA
CVSS 7.0
CVE-2025-27477 HIGH
Windows Telephony Service - Buffer Overflow
CVSS 8.8
CVE-2025-27199 HIGH
Animate <24.0.7, 23.0.10 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-27198 HIGH
Photoshop Desktop <26.4.1 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-27196 HIGH
Premiere Pro < 24.6.5 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2025-27195 HIGH
Media Encoder <25.1, 24.6.4 - Buffer Overflow
CVSS 7.8
CVE-2025-27193 HIGH
Bridge <15.0.2 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-26674 HIGH
Windows Media - Authenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-26668 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Remote Code Execution via RRAS Heap Overflow
CVSS 7.5
CVE-2025-26666 HIGH
Windows Media - Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-26639 HIGH
Windows USB Print Driver < 10.0.19044.5737 - Authenticated Privilege Escalation via Integer Overflow
CVSS 7.8
Details
Vulnerabilities 2,325
Exploit Likelihood High