VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 56 of 135
  • CVE-2025-29979HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-24063HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2024-6031HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target modem in order…

  • CVE-2025-1045HigApr 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this…

  • CVE-2025-2497HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-1656HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2025-1275HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the…

  • CVE-2025-1273HigApr 15, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2025-30299HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-30295HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-29811HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27752HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-27490HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27199HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-27198HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-27196HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-27195HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-27193HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-26674HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

  • CVE-2025-26666HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.