CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-38255 HIGH
Microsoft SQL Server 2016-2019 Native Client - Remote Code Execution
CVSS 8.8
CVE-2024-10525 CRITICAL
Eclipse Mosquitto 1.3.2-2.0.18 - Heap-based Buffer Overflow via Crafted SUBACK Packet
CVSS 9.8
CVE-2024-9632 HIGH
Red Hat Enterprise Linux - Heap-based Buffer Overflow in X.org Server via _XkbSetCompatMap
CVSS 7.8
CVE-2024-8594 HIGH
AutoCAD 2025 < 2025.1.1 - Heap-based Buffer Overflow via Malicious MODEL File
CVSS 7.8
CVE-2024-8591 HIGH
Autodesk AutoCAD - Heap-Based Buffer Overflow
CVSS 7.8
CVE-2024-8587 HIGH
Autodesk AutoCAD - Heap Based Buffer Overflow
CVSS 7.8
CVE-2024-43587 MEDIUM
Microsoft Edge Chromium < 130.0.2849.46 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 5.9
CVE-2024-43579 HIGH
Microsoft Edge Chromium < 130.0.2849.46 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.6
CVE-2024-43578 HIGH
Microsoft Edge Chromium < 130.0.2849.46 - Remote Code Execution
CVSS 7.6
CVE-2024-47964 HIGH
Delta Electronics CNCSoft-G2 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-45143 HIGH
Adobe Substance 3D Stager <=3.0.3 - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-45139 HIGH
Adobe Substance 3D Stager <=3.0.3 - Heap Buffer Overflow Code Execution
CVSS 7.8
CVE-2024-47417 HIGH
Adobe Animate < 23.0.8 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-43611 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43608 HIGH
Windows Server RCE in Routing and Remote Access Service
CVSS 8.8
CVE-2024-43607 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43593 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43592 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43589 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43564 HIGH
Windows Server RRAS Remote Code Execution (2008, 2012, 2016, 2019, 2022)
CVSS 8.8
CVE-2024-43560 HIGH
Windows Storage Port Driver - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-43528 HIGH
Windows 10/11 Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-43527 HIGH
Windows 11 24H2 < 10.0.26100.2033 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2024-43526 MEDIUM
Windows Mobile Broadband Driver - Remote Code Execution
CVSS 6.8
CVE-2024-43525 MEDIUM
Windows Mobile Broadband Driver - Remote Code Execution
CVSS 6.8
Details
Vulnerabilities 2,327
Exploit Likelihood High