VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 52 of 135
  • CVE-2025-61832HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-61824HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-61816HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-9458HigNov 7, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-54496HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.

  • CVE-2025-20735HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435349; Issue ID: MSV-4051.

  • CVE-2025-20733HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00441509; Issue ID: MSV-4138.

  • CVE-2025-20728HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276.

  • CVE-2025-11464HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability…

  • CVE-2025-54268HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-61804HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.13, 24.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-54282HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-59275HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59255HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59242HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59191HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58722HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55697HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

  • CVE-2025-7983HigSep 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this…

  • CVE-2025-8894HigSep 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.