CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,326 vulnerabilities with CWE-122
CVE-2025-21382 HIGH
Windows Graphics Component - Elevation of Privilege via Integer Overflow
CVSS 7.8
CVE-2025-21378 HIGH
Windows 10 1507-24H2 and Windows Server 2012-2016 - Elevation of Privilege via CSC Service Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-21356 HIGH
Microsoft Office Visio - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2025-21339 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21333 HIGH KEV
Windows Hyper-V NT Kernel Integration VSP - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2025-21306 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21305 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21303 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21302 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21286 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21282 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21273 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21266 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21256 MEDIUM
Windows Digital Media - Elevation of Privilege via Out-of-bounds Read
CVSS 6.6
CVE-2025-21252 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21250 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21248 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21246 HIGH
Windows Telephony Service - Remote Code Execution
CVSS 8.8
CVE-2025-21245 HIGH
Windows Telephony Service - Remote Code Execution
CVSS 8.8
CVE-2025-21241 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21240 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21239 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21238 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21237 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2025-21236 HIGH
Windows Telephony Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,326
Exploit Likelihood High