CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 31 of 52
- CVE-2025-2152MEDIUMCVSS 6.3EG 6.32025-03-10
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. Th…
- CVE-2025-2153MEDIUMCVSS 5.0EG 5.02025-03-10
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to …
- CVE-2025-22134MEDIUMCVSS 5.5EG 5.52025-01-13
When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a b…
- CVE-2025-22258MEDIUMCVSS 6.5EG 6.52025-10-14
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, F…
- CVE-2025-22880HIGHCVSS 7.8EG 7.82025-02-07
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this v…
- CVE-2025-22881HIGHCVSS 7.8EG 7.82025-02-26
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this v…
- CVE-2025-22920MEDIUMCVSS 5.3EG 5.32025-02-18
A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Servi…
- CVE-2025-2308MEDIUMCVSS 5.3EG 5.32025-03-14
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads to heap-based buffer overflow. An atta…
- CVE-2025-2309MEDIUMCVSS 5.3EG 5.32025-03-14
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is r…
- CVE-2025-2310MEDIUMCVSS 5.3EG 5.32025-03-14
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a req…
- CVE-2025-23123CRITICALCVSS 10.0EG 10.02025-05-19
A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow vulnerability in the UniFi Protect Cameras (Version 4.75.43 and earlier) firmware.
- CVE-2025-23308LOWCVSS 3.3EG 3.32025-09-24
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may…
- CVE-2025-23317CRITICALCVSS 9.1EG 9.12025-08-06
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code exe…
- CVE-2025-2337MEDIUMCVSS 6.3EG 6.32025-03-16
A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated r…
- CVE-2025-2338MEDIUMCVSS 6.3EG 6.32025-03-16
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remo…
- CVE-2025-2368MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the c…
- CVE-2025-24048HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-24050HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-24051HIGHCVSS 8.8EG 8.82025-03-11
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-24056HIGHCVSS 8.8EG 8.82025-03-11
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
- CVE-2025-24057HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-24063HIGHCVSS 7.8EG 7.82025-05-13
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-24066HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2025-24067HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-24439HIGHCVSS 7.8EG 7.82025-03-11
Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-24443HIGHCVSS 7.8EG 7.82025-03-11
Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact…
- CVE-2025-24453HIGHCVSS 7.8EG 7.82025-03-11
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2025-24477MEDIUMCVSS 4.2EG 4.22025-07-15
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
- CVE-2025-24797CRITICALCVSS 9.4EG 9.42025-04-15
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentiall…
- CVE-2025-2497HIGHCVSS 7.8EG 7.82025-04-15
A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- CVE-2025-24985CRITICALCVSS 7.8EG 9.0⚠ KEV2025-03-11
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- CVE-2025-24993CRITICALCVSS 7.8EG 9.0⚠ KEV2025-03-11
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2025-24995HIGHCVSS 7.8EG 7.82025-03-11
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-25249HIGHCVSS 7.4EG 8.12026-01-13
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, …
- CVE-2025-2531HIGHCVSS 7.8EG 7.82025-03-25
Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required …
- CVE-2025-2584MEDIUMCVSS 5.0EG 5.02025-03-21
A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipul…
- CVE-2025-2592MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to…
- CVE-2025-2618CRITICALCVSS 9.8EG 9.82025-03-22
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffe…
- CVE-2025-26416CRITICALCVSS 9.8EG 9.82025-09-02
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2025-26455HIGHCVSS 7.8EG 7.82025-09-04
In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…
- CVE-2025-26634HIGHCVSS 7.5EG 7.52025-03-11
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
- CVE-2025-26639HIGHCVSS 7.8EG 7.82025-04-08
Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-26666HIGHCVSS 7.8EG 7.82025-04-08
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
- CVE-2025-26668HIGHCVSS 7.5EG 7.52025-04-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-26674HIGHCVSS 7.8EG 7.82025-04-08
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
- CVE-2025-27091HIGHCVSS 7.5EG 7.52025-02-20
OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulner…
- CVE-2025-27171HIGHCVSS 7.8EG 7.82025-03-11
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2025-27173HIGHCVSS 7.8EG 7.82025-03-11
Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac…
- CVE-2025-27177HIGHCVSS 7.8EG 7.82025-03-11
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in…
- CVE-2025-27193HIGHCVSS 7.8EG 7.82025-04-08
Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →