CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-11514 HIGH
IrfanView ECW File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-11513 HIGH
IrfanView ECW File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-11511 HIGH
IrfanView XCF Plugin - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-11509 HIGH
IrfanView SVG File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-6816 HIGH
IrfanView PSP File Parser - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-6246 HIGH
Wyze Cam v3 - Remote Code Execution
CVSS 8.8
CVE-2024-5876 HIGH
IrfanView formats < 4.66.2 - Heap-based Buffer Overflow in PSP File Parser
CVSS 7.8
CVE-2024-37041 HIGH
QNAP QTS and QuTS hero - Heap-based Buffer Overflow
CVSS 7.2
CVE-2024-10204 HIGH
eDrawings SOLIDWORKS 2024-2025 - Heap-based Buffer Overflow and Uninitialized Variable in X_B and SAT File Parsing
CVSS 7.8
CVE-2024-7730 HIGH
QEMU < 9.1.0 - Heap-based Buffer Overflow in virtio-snd Input Callback
CVSS 7.4
CVE-2024-3447 MEDIUM
QEMU - Heap-based Buffer Overflow in SDHCI Device Emulation
CVSS 6.0
CVE-2024-48075 MEDIUM
Real Time Logic SharkSSL <09/09/24 - DoS
CVSS 5.3
CVE-2024-49509 HIGH
InDesign Desktop <ID19.5 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-49508 HIGH
InDesign Desktop <ID19.5 - Buffer Overflow
CVSS 7.8
CVE-2024-49507 HIGH
InDesign Desktop <ID19.5 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-49525 HIGH
Adobe Substance 3D Painter <=10.1.0 - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-49517 HIGH
Adobe Substance 3D Painter <=10.1.0 - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-47431 HIGH
Adobe Substance 3D Painter <=10.1.0 - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-47450 HIGH
Illustrator < 28.7.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-33505 MEDIUM
FortiAnalyzer 6.4.0-7.4.2 and FortiManager 6.0.0-7.4.2 - Heap-based Buffer Overflow via HTTP Requests
CVSS 5.6
CVE-2024-49030 HIGH
Microsoft Excel - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-49017 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-49015 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-49013 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Native Client
CVSS 8.8
CVE-2024-49012 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,327
Exploit Likelihood High