CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 34 of 52
- CVE-2025-47125HIGHCVSS 7.8EG 7.82025-07-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2025-47131HIGHCVSS 7.8EG 7.82025-07-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2025-47134HIGHCVSS 7.8EG 7.82025-07-08
InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction …
- CVE-2025-47162HIGHCVSS 8.4EG 8.42025-06-10
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-47169HIGHCVSS 7.8EG 7.82025-06-10
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-47174HIGHCVSS 7.8EG 7.82025-06-10
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-47436CRITICALCVSS 9.8EG 9.82025-05-14
Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but …
- CVE-2025-47814MEDIUMCVSS 4.5EG 4.52025-05-10
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
- CVE-2025-47815MEDIUMCVSS 4.5EG 4.52025-05-10
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.
- CVE-2025-47868CRITICALCVSS 9.8EG 9.82025-06-16
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither …
- CVE-2025-47981CRITICALCVSS 9.8EG 9.82025-07-08
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- CVE-2025-47987HIGHCVSS 7.8EG 7.82025-07-08
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
- CVE-2025-47998HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-48005CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker c…
- CVE-2025-48071HIGHCVSS 7.8EG 7.82025-07-31
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operatio…
- CVE-2025-48379HIGHCVSS 7.1EG 7.12025-07-01
Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without ch…
- CVE-2025-48592HIGHCVSS 7.5EG 7.52025-12-08
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…
- CVE-2025-48723HIGHCVSS 8.1EG 8.12026-02-11
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in …
- CVE-2025-48724HIGHCVSS 8.1EG 8.12026-02-11
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in …
- CVE-2025-48797HIGHCVSS 7.3EG 7.32025-05-27
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashe…
- CVE-2025-48805HIGHCVSS 7.8EG 7.82025-07-08
Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
- CVE-2025-48824HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-48910MEDIUMCVSS 5.5EG 5.52025-06-06
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-48990HIGHCVSS 8.6EG 8.62025-06-02
NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at `dst[len]`. When `len` equals the size of the destination buffer (256…
- CVE-2025-49560HIGHCVSS 7.8EG 7.82025-08-12
Substance3D - Viewer versions 0.25 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interactio…
- CVE-2025-49604MEDIUMCVSS 5.4EG 5.42025-07-09
For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment…
- CVE-2025-49657HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49663HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49666HIGHCVSS 7.2EG 7.22025-07-08
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
- CVE-2025-49668HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49669HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49670HIGHCVSS 6.5EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49672HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49673HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49674HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49676HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49683HIGHCVSS 7.8EG 7.82025-07-08
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
- CVE-2025-49691HIGHCVSS 8.0EG 8.02025-07-08
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2025-49696HIGHCVSS 8.4EG 8.42025-07-08
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49697HIGHCVSS 8.4EG 8.42025-07-08
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49705HIGHCVSS 7.8EG 7.82025-07-08
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2025-49717HIGHCVSS 8.5EG 8.52025-07-08
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2025-49721HIGHCVSS 7.8EG 7.82025-07-08
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-49727HIGHCVSS 7.0EG 7.02025-07-08
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2025-49729HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-49730HIGHCVSS 7.8EG 7.82025-07-08
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
- CVE-2025-49732HIGHCVSS 7.8EG 7.82025-07-08
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-49742HIGHCVSS 7.8EG 7.82025-07-08
Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
- CVE-2025-49744HIGHCVSS 7.0EG 7.02025-07-08
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-49753HIGHCVSS 8.8EG 8.82025-07-08
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →