VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 55 of 135
  • CVE-2025-47134HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-47103HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-43591HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-43582HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user, scope unchanged. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2025-49742HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.

  • CVE-2025-49732HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49721HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-49705HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-48805HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

  • CVE-2025-50130HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC CO., LTD. Opening V9 files or X1 files specially crafted by an attacker on the affected product may lead to arbitrary code execution.

  • CVE-2025-6660HigJun 25, 2025
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in…

  • CVE-2025-47107HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 20.2, 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-47174HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-47169HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-32718HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32713HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30317HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-30330HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-30388HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.04

    Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

  • CVE-2025-30376HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.