CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-43523 MEDIUM
Windows Mobile Broadband Driver - Remote Code Execution
CVSS 6.8
CVE-2024-43522 HIGH
Windows 11 22H2 < 10.0.22621.4317 and 23H2 < 10.0.22631.4317 - Local Privilege Escalation in Local Security Authority
CVSS 7.0
CVE-2024-43518 HIGH
Windows Telephony Server - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-43517 HIGH
Microsoft Windows 10 1507-24H2 and Windows Server 2008 - Remote Code Execution via ActiveX Data Objects
CVSS 8.8
CVE-2024-43480 MEDIUM
Azure Service Fabric for Linux - Remote Code Execution
CVSS 6.6
CVE-2024-43453 HIGH
Microsoft Windows Server 2008 < 10.0.14393.7428 - Heap Buffer Overflow
CVSS 8.8
CVE-2024-38265 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 8.8
CVE-2024-38261 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 7.8
CVE-2024-38212 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 8.8
CVE-2024-41981 HIGH
Simcenter Femap <V2406 - Buffer Overflow
CVSS 7.8
CVE-2024-6444 MEDIUM
Zephyr < 3.6.0 - Heap-based Buffer Overflow in OTS Client olcp_ind_handler
CVSS 6.3
CVE-2024-45872 MEDIUM
Bandisoft BandiView 7.05 - Heap-based Buffer Overflow via PSD File Parsing
CVSS 6.3
CVE-2024-20522 MEDIUM
Cisco Small Business RV042-325 - DoS
CVSS 6.5
CVE-2024-20517 MEDIUM
Cisco Small Business RV042-325 - DoS
CVSS 6.8
CVE-2024-20516 MEDIUM
Cisco Small Business RV042-325 - DoS
CVSS 6.8
CVE-2024-46264 HIGH
cute_png v1.05 - Heap-based Buffer Overflow via cp_find()
CVSS 7.8
CVE-2024-7674 HIGH
Autodesk Navisworks - Heap-based Buffer Overflow via DWFX File Parsing
CVSS 7.8
CVE-2024-7673 HIGH
Autodesk Navisworks - Heap-based Buffer Overflow via DWFX File Parsing
CVSS 7.8
CVE-2024-45993 MEDIUM
giflib 5.2.2 - Heap-based Buffer Overflow via gif2rgb
CVSS 6.5
CVE-2024-38796 MEDIUM
EDK2 < edk2-stable202405 - Heap-based Buffer Overflow in PeCoffLoaderRelocateImage()
CVSS 5.9
CVE-2024-46632 MEDIUM
Assimp 5.4.3 - Heap-based Buffer Overflow in MD5Importer::LoadMD5MeshFile
CVSS 4.3
CVE-2024-46488 MEDIUM
sqlite-vec 0.1.1 - Heap-based Buffer Overflow via npy_token_next
CVSS 5.5
CVE-2024-20508 MEDIUM
Cisco Unified Threat Defense Snort IPS Engine - Unauthenticated Denial of Service via Crafted HTTP Request
CVSS 5.8
CVE-2024-46461 HIGH
VLC media player <= 3.0.20 - Denial of Service and Remote Code Execution via Malicious MMS Stream
CVSS 8.0
CVE-2024-7018 HIGH
Chrome < 124.0.6367.78 - Heap-based Buffer Overflow in PDF
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High