VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 57 of 135
  • CVE-2025-26639HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-2531HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that…

  • CVE-2025-1651HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-1429HigMar 13, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2025-2019HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this…

  • CVE-2025-27173HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-27177HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-27171HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-24453HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-24443HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-24439HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-24995HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24067HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24066HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24057HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-24050HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24048HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21180HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.

  • CVE-2025-21169HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer versions 14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-22881HigFeb 26, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…