VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 101 of 160
  • CVE-2025-57740HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions,…

  • CVE-2025-57638HigSep 23, 2025
    risk 0.49cvss 7.5epss 0.00

    Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.

  • CVE-2025-57637HigSep 23, 2025
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowing attackers to cause a denial of service or execute arbitrary code.

  • CVE-2025-51005HigSep 23, 2025
    risk 0.49cvss 7.5epss 0.00

    A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the program incorrectly handles memory in the checksum calculation logic at do_checksum_math_liveplay in tcpliveplay.c, leading to a possible…

  • CVE-2025-56394HigSep 23, 2025
    risk 0.49cvss 7.5epss 0.00

    Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.

  • CVE-2025-40928HigSep 8, 2025
    risk 0.49cvss 7.5epss 0.01

    JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

  • CVE-2025-36853HigSep 8, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of…

  • CVE-2025-50617HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wps_set in the payload, which can cause the program to crash and potentially…

  • CVE-2025-53783HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

  • CVE-2025-5462HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated…

  • CVE-2025-53816HigJul 17, 2025
    risk 0.49cvss 7.5epss 0.01

    7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

  • CVE-2025-49744HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-5479HigJun 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. An attacker must first obtain the ability…

  • CVE-2025-5477HigJun 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a…

  • CVE-2025-48990HigJun 2, 2025
    risk 0.49cvss —epss 0.00

    NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at `dst[len]`. When `len` equals the size of the destination buffer (256 bytes), that extra `'\0'` write…

  • CVE-2025-2900HigMay 14, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption…

  • CVE-2025-3713HigMay 9, 2025
    risk 0.49cvss 7.5epss 0.01

    The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to perform a denial-of-service attack.

  • CVE-2025-3712HigMay 9, 2025
    risk 0.49cvss 7.5epss 0.01

    The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to perform a denial-of-service attack.

  • CVE-2025-32400HigMay 7, 2025
    risk 0.49cvss 7.5epss 0.00

    An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.

  • CVE-2025-32397HigMay 7, 2025
    risk 0.49cvss 7.5epss 0.00

    An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.