CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,325 vulnerabilities with CWE-122
CVE-2025-21222 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21221 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21205 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-29769 MEDIUM
libvips < 8.16.1 - Heap-based Buffer Overflow via HEIF Save Operation
CVSS 5.5
CVE-2025-3159 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in ASE File Handler
CVSS 5.3
CVE-2025-3158 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in LWO File Handler
CVSS 5.3
CVE-2025-29070 HIGH
lcms2 2.16 - Heap-based Buffer Overflow in thesmooth2()
CVSS 7.5
CVE-2025-29069 HIGH
lcms2 2.16 - Heap-based Buffer Overflow in UnrollChunkyBytes Function
CVSS 7.3
CVE-2025-2924 LOW
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5HL__fl_deserialize
CVSS 3.3
CVE-2025-2923 LOW
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5F_addr_encode_len
CVSS 3.3
CVE-2025-31164 MEDIUM
fig2dev 3.2.9a - Heap-based Buffer Overflow via create_line_with_spline
CVSS 6.6
CVE-2025-2915 LOW
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5F__accum_free
CVSS 3.3
CVE-2025-2914 LOW
HDF5 < 1.14.6 - Heap-Based Buffer Overflow in H5FS__sinfo_Srialize_Sct_cb
CVSS 3.3
CVE-2025-2912 LOW
HDF5 < 2.0.0 - Heap-Based Buffer Overflow in H5O_msg_flush
CVSS 3.3
CVE-2025-2849 LOW
UPX < 5.0.0 - Heap-Based Buffer Overflow in PackLinuxElf64::un_DT_INIT
CVSS 3.3
CVE-2025-30216 CRITICAL
CryptoLib < 1.4.0 - Heap-based Buffer Overflow in Crypto_TM_ProcessSecurity
CVSS 9.4
CVE-2025-2531 HIGH
Luxion KeyShot < 2025.1 - Heap-based Buffer Overflow in DAE File Parser
CVSS 7.8
CVE-2025-2757 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in MD5 File Handler
CVSS 6.3
CVE-2025-2756 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in AC3D File Handler
CVSS 6.3
CVE-2025-2754 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in AC3D File Handler
CVSS 6.3
CVE-2025-2618 CRITICAL
D-Link DAP-1620 1.03 - Buffer Overflow
CVSS 9.8
CVE-2025-2592 MEDIUM
Open Asset Import Library Assimp 5.4.3 - Heap-Based Buffer Overflow in CSMLoader
CVSS 6.3
CVE-2025-2584 MEDIUM
WebAssembly wabt 1.0.36 - Heap-Based Buffer Overflow in BinaryReaderInterp::GetReturnCallDropKeepCount
CVSS 5.0
CVE-2025-0755 HIGH
libbson < 1.27.5 - Heap-based Buffer Overflow via BSON Document Size Exceeding INT32_MAX
CVSS 8.4
CVE-2025-29912 CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow via Telecommand Packet Frame Length Field
CVSS 9.8
Details
Vulnerabilities 2,325
Exploit Likelihood High