CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-7272 MEDIUM
FFmpeg < 5.1.6 - Heap-based Buffer Overflow in fill_audiodata
CVSS 6.3
CVE-2024-43168 MEDIUM
Red Hat Enterprise Linux 6-9 - Heap-based Buffer Overflow in Unbound cfg_mark_ports
CVSS 4.8
CVE-2024-7534 HIGH
Google Chrome < 127.0.6533.99 - Heap Buffer Overflow in Layout via Crafted HTML Page
CVSS 8.8
CVE-2024-6994 HIGH
Google Chrome < 127.0.6533.72 - Heap-based Buffer Overflow in Layout
CVSS 8.8
CVE-2024-7055 MEDIUM
FFmpeg < 4.3.8 - Heap-based Buffer Overflow in pnm_decode_frame
CVSS 6.3
CVE-2024-7546 HIGH
oFono - Heap-based Buffer Overflow in STK Command PDU Parser
CVSS 7.8
CVE-2024-7545 HIGH
oFono - Heap-based Buffer Overflow in STK Command PDU Parsing
CVSS 7.8
CVE-2024-7544 HIGH
oFono - Heap-based Buffer Overflow in STK Command PDU Parser
CVSS 7.8
CVE-2024-7543 HIGH
oFono - Heap-based Buffer Overflow in STK Command PDU Parser
CVSS 7.8
CVE-2024-39392 HIGH
Adobe InDesign < 18.5.3 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-6873 HIGH
ClickHouse 23.8.0-24.6.1 - Unauthenticated Heap-based Buffer Overflow via Native Interface
CVSS 8.1
CVE-2024-41440 MEDIUM
hicolor 0.5.0 - Heap-based Buffer Overflow in png_quantize()
CVSS 6.2
CVE-2024-41438 MEDIUM
hicolor 0.5.0 - Heap-based Buffer Overflow in cp_stored Function
CVSS 6.2
CVE-2024-41437 MEDIUM
hicolor 0.5.0 - Heap-based Buffer Overflow in cp_unfilter() via Crafted PNG File
CVSS 5.5
CVE-2024-32671 CRITICAL
Samsung Escargot 4.0.0 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2024-40764 HIGH
SonicOS < 6.5.4.v-21s-rc2457 - Unauthenticated Denial of Service via Heap-based Buffer Overflow
CVSS 7.5
CVE-2024-40129 CRITICAL
Open5GS v2.6.4 - Heap-based Buffer Overflow in /lib/pfcp/context.c
CVSS 9.8
CVE-2024-39518 HIGH
Junos OS DoS via Telemetry Sensor Memory Leak
CVSS 7.5
CVE-2024-37310 CRITICAL
EVerest everest-core < 2024.3.1 and 2024.4.0-2024.6.0 - Heap-based Buffer Overflow in v2g_incoming_v2gtp
CVSS 9.0
CVE-2024-39883 HIGH
Delta Electronics CNCSoft-G2 - Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-20785 HIGH
InDesign Desktop <ID19.3,ID18.5.2 - Buffer Overflow
CVSS 7.8
CVE-2024-20783 HIGH
InDesign Desktop <ID19.3,ID18.5.2 - RCE
CVSS 7.8
CVE-2024-20781 HIGH
InDesign Desktop <ID19.3,ID18.5.2 - Buffer Overflow
CVSS 7.8
CVE-2024-38088 HIGH
SQL Server Native Client OLE DB Provider - Remote Code Execution
CVSS 8.8
CVE-2024-38079 HIGH
Windows Graphics Component - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High