CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,326 vulnerabilities with CWE-122
CVE-2024-56827 MEDIUM
Red Hat Enterprise Linux 9 - Heap-based Buffer Overflow in opj_decompress
CVSS 5.6
CVE-2024-56826 MEDIUM
Red Hat Enterprise Linux 9 - Heap-based Buffer Overflow in opj_decompress
CVSS 5.6
CVE-2024-51737 HIGH
RediSearch < 2.6.24, 2.8.21, 2.10.10 - LIMIT Integer Overflow Code Execution
CVSS 7.0
CVE-2024-51480 HIGH
RedisTimeSeries Commands - Integer Overflow Code Execution
CVSS 7.0
CVE-2024-55627 MEDIUM
Suricata < 7.0.8 - Integer Underflow in TCP Stream Handling
CVSS 5.9
CVE-2024-13051 HIGH
Ashlar-Vellum Graphite - Heap-based Buffer Overflow in VC6 File Parsing
CVSS 7.8
CVE-2024-13050 HIGH
Ashlar-Vellum Graphite - Heap-based Buffer Overflow in VC6 File Parsing
CVSS 7.8
CVE-2024-56737 HIGH
GNU GRUB2 < 2.12 - Heap-based Buffer Overflow in HFS Filesystem Parser
CVSS 8.8
CVE-2024-56732 HIGH
HarfBuzz 8.5.0-10.0.1 - Heap-based Buffer Overflow in hb_cairo_glyphs_from_buffer
CVSS 8.8
CVE-2024-12670 HIGH
Autodesk Navisworks 2025-2025.4 - Heap-based Buffer Overflow via DWFX File Parsing
CVSS 7.8
CVE-2024-12669 HIGH
Autodesk Navisworks 2025-2025.4 - Heap-based Buffer Overflow via DWFX File Parsing
CVSS 7.8
CVE-2024-12179 HIGH
Autodesk Navisworks 2025-2025.4 - Heap-based Buffer Overflow via DWFX File Parsing
CVSS 7.8
CVE-2024-49775 CRITICAL
Opcenter Execution Foundation, Opcenter Intelligence, Opcenter Qual...
CVSS 9.8
CVE-2024-8798 HIGH
Zephyr < 3.7.0 - Heap-based Buffer Overflow in OTS Client OLCP Indication Handler
CVSS 7.5
CVE-2024-52059 HIGH
RTI Connext Professional <7.3.0.2-6.1.2.17 - Buffer Overflow
CVSS 7.8
CVE-2024-49138 HIGH KEV
Windows Common Log File System Driver - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-49125 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2024-49104 HIGH
Windows Routing and Remote Access Service - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-49102 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Remote Code Execution via RRAS Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-49094 MEDIUM
Windows 10/11, Server 2019/2022/2025 Elevation of Privilege via WWAN Service
CVSS 6.6
CVE-2024-49089 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Remote Code Execution in RRAS
CVSS 7.2
CVE-2024-49086 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2024-49085 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022, 2025)
CVSS 8.8
CVE-2024-49081 MEDIUM
Windows 10/11, Server 2019/2022/2025 Elevation of Privilege via WWAN Service
CVSS 6.6
CVE-2024-49080 HIGH
Windows IP Routing Management Snapin - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,326
Exploit Likelihood High