CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 4 of 66
- CVE-2025-11778CRITICALCVSS 9.8EG 9.82025-12-02
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.
- CVE-2025-65085CRITICALCVSS 9.8EG 9.82025-11-25
A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.
- CVE-2025-64693CRITICALCVSS 9.8EG 9.82025-11-25
Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code …
- CVE-2025-60724CRITICALCVSS 9.8EG 9.82025-11-11
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2025-58447CRITICALCVSS 9.8EG 9.82025-09-09
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the login server, remote attacker to overwrite adjacent session …
- CVE-2025-26416CRITICALCVSS 9.8EG 9.82025-09-02
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2025-34522CRITICALCVSS 9.8EG 9.82025-08-27
A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bou…
- CVE-2025-34523CRITICALCVSS 9.8EG 9.82025-08-27
A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when process…
- CVE-2025-54462CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to arbitrary code execution. An attacker can prov…
- CVE-2025-53853CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the ISHNE parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted ISHNE ECG annotations file can lead to arbitrary code execution. A…
- CVE-2025-53557CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can pro…
- CVE-2025-53511CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can pro…
- CVE-2025-48005CRITICALCVSS 9.8EG 9.82025-08-25
A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker c…
- CVE-2025-53766CRITICALCVSS 9.8EG 9.82025-08-12
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2025-54951CRITICALCVSS 9.8EG 9.82025-08-07
A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit cea9…
- CVE-2025-54949CRITICALCVSS 9.8EG 9.82025-08-07
A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493dae6d2d43f8c424e7be4721abe5242be
- CVE-2025-7208CRITICALCVSS 9.8EG 9.82025-07-09
A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. The manipulation leads to heap-based buffer overflow. The…
- CVE-2025-47981CRITICALCVSS 9.8EG 9.82025-07-08
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- CVE-2025-20680CRITICALCVSS 9.8EG 9.82025-07-08
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch I…
- CVE-2025-20260CRITICALCVSS 9.8EG 9.82025-06-18
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. Th…
- CVE-2025-47868CRITICALCVSS 9.8EG 9.82025-06-16
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither …
- CVE-2025-20672CRITICALCVSS 9.8EG 9.82025-06-02
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch I…
- CVE-2025-40906CRITICALCVSS 9.8EG 9.82025-05-16
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was …
- CVE-2025-47436CRITICALCVSS 9.8EG 9.82025-05-14
Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but …
- CVE-2025-3277CRITICALCVSS 9.8EG 9.82025-04-14
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated si…
- CVE-2025-2618CRITICALCVSS 9.8EG 9.82025-03-22
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffe…
- CVE-2025-29912CRITICALCVSS 9.8EG 9.82025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versi…
- CVE-2025-29911CRITICALCVSS 9.8EG 9.82025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critic…
- CVE-2024-50698CRITICALCVSS 9.8EG 9.82025-01-24
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content.
- CVE-2024-55192CRITICALCVSS 9.8EG 9.82025-01-23
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
- CVE-2024-12084CRITICALCVSS 9.8EG 9.82025-01-15
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacke…
- CVE-2024-49775CRITICALCVSS 9.8EG 9.82024-12-16
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS…
- CVE-2024-10525CRITICALCVSS 9.8EG 9.82024-10-30
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. T…
- CVE-2024-21416CRITICALCVSS 9.8EG 9.82024-09-10
Windows TCP/IP Remote Code Execution Vulnerability
- CVE-2024-40754CRITICALCVSS 9.8EG 9.82024-09-10
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
- CVE-2024-33698CRITICALCVSS 9.8EG 9.82024-09-10
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versi…
- CVE-2024-32671CRITICALCVSS 9.8EG 9.82024-07-29
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
- CVE-2024-40129CRITICALCVSS 9.8EG 9.82024-07-16
Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.
- CVE-2024-38077CRITICALCVSS 9.8EG 9.82024-07-09
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-38076CRITICALCVSS 9.8EG 9.82024-07-09
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-37080CRITICALCVSS 9.8EG 9.82024-06-18
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potent…
- CVE-2024-4323CRITICALCVSS 9.8EG 9.82024-05-20
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code exe…
- CVE-2024-32621CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.
- CVE-2024-32615CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.
- CVE-2024-29157CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-34249CRITICALCVSS 9.8EG 9.82024-05-06
wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.
- CVE-2023-26793CRITICALCVSS 9.8EG 9.82024-05-01
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
- CVE-2024-32038CRITICALCVSS 9.8EG 9.82024-04-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manage…
- CVE-2024-29204CRITICALCVSS 9.8EG 9.82024-04-19
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
- CVE-2024-24996CRITICALCVSS 9.8EG 9.82024-04-19
A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →