VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 70 of 160
  • CVE-2026-20809HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

  • CVE-2025-15279HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-15277HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-12840HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is…

  • CVE-2025-12839HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is…

  • CVE-2025-12495HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is…

  • CVE-2025-14935HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to exploit this vulnerability…

  • CVE-2025-9457HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2025-10881HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2025-64680HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64679HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62470HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62458HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62454HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-8351HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avira Antivirus engine when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for…

  • CVE-2025-10101HigDec 1, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast…

  • CVE-2025-46373HigNov 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker…

  • CVE-2025-61838HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61837HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Format Plugins versions 1.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-62201HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.