CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 15 of 66
- CVE-2025-21410HIGHCVSS 8.8EG 8.82025-02-11
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2025-21407HIGHCVSS 8.8EG 8.82025-02-11
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21371HIGHCVSS 8.8EG 8.82025-02-11
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21369HIGHCVSS 8.8EG 8.82025-02-11
Microsoft Digest Authentication Remote Code Execution Vulnerability
- CVE-2025-21368HIGHCVSS 8.8EG 8.82025-02-11
Microsoft Digest Authentication Remote Code Execution Vulnerability
- CVE-2025-21208HIGHCVSS 8.8EG 8.82025-02-11
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2025-21200HIGHCVSS 8.8EG 8.82025-02-11
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21190HIGHCVSS 8.8EG 8.82025-02-11
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2019-15690HIGHCVSS 8.8EG 8.82025-01-24
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in re…
- CVE-2023-50739HIGHCVSS 8.8EG 8.82025-01-18
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2025-0434HIGHCVSS 8.8EG 8.82025-01-15
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-21417HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21413HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21411HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21409HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21339HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21306HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21305HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21303HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21302HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21286HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21282HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21273HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21266HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21252HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21250HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21248HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21246HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21245HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21241HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21240HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21239HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21238HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21237HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21236HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21233HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21223HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21178HIGHCVSS 8.8EG 8.82025-01-14
Visual Studio Remote Code Execution Vulnerability
- CVE-2024-56737HIGHCVSS 8.8EG 8.82024-12-29
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.
- CVE-2024-56732HIGHCVSS 8.8EG 8.82024-12-27
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
- CVE-2024-49125HIGHCVSS 8.8EG 8.82024-12-12
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-49104HIGHCVSS 8.8EG 8.82024-12-12
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-49102HIGHCVSS 8.8EG 8.82024-12-12
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-49086HIGHCVSS 8.8EG 8.82024-12-12
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-49085HIGHCVSS 8.8EG 8.82024-12-12
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-49080HIGHCVSS 8.8EG 8.82024-12-12
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
- CVE-2024-49017HIGHCVSS 8.8EG 8.82024-11-12
SQL Server Native Client Remote Code Execution Vulnerability
- CVE-2024-49015HIGHCVSS 8.8EG 8.82024-11-12
SQL Server Native Client Remote Code Execution Vulnerability
- CVE-2024-49013HIGHCVSS 8.8EG 8.82024-11-12
SQL Server Native Client Remote Code Execution Vulnerability
- CVE-2024-49012HIGHCVSS 8.8EG 8.82024-11-12
SQL Server Native Client Remote Code Execution Vulnerability
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →