CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-35271 HIGH
SQL Server 2016/2017/2019/2022 RCE via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-35256 HIGH
SQL Server 2016/2017/2019/2022 - Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21449 HIGH
SQL Server 2016/2017/2019/2022 - Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21425 HIGH
SQL Server 2016-2022 Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21415 HIGH
SQL Server 2016-2022 Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21414 HIGH
SQL Server 2016-2022 Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21398 HIGH
SQL Server 2016-2022 - Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21373 HIGH
SQL Server 2016-2022 Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-21335 HIGH
SQL Server 2016-2022 Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-21333 HIGH
SQL Server 2016-2022 Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-21331 HIGH
Microsoft SQL Server 2016-2022 Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2024-21317 HIGH
SQL Server 2016-2022 Remote Code Execution via Native Client OLE DB Provider
CVSS 8.8
CVE-2024-20701 HIGH
SQL Server Native Client OLE DB Provider - Remote Code Execution
CVSS 8.8
CVE-2024-21778 HIGH
Realtek rtl819x Jungle SDK 3.4.11 - Heap-based Buffer Overflow via Crafted .dat File
CVSS 7.2
CVE-2024-6383 MEDIUM
MongoDB C Driver <1.27.1 - Buffer Overflow
CVSS 5.3
CVE-2024-29508 LOW
Artifex Ghostscript <10.03.0 - Info Disclosure
CVSS 3.3
CVE-2024-32229 HIGH
FFmpeg 7.0 - Heap-based Buffer Overflow in copy_column
CVSS 8.4
CVE-2024-39133 MEDIUM
zziplib v0.13.77 - Heap-based Buffer Overflow in __zzip_parse_root_directory
CVSS 4.3
CVE-2024-38950 MEDIUM
Libde265 1.0.15 - Heap-based Buffer Overflow via Crafted Payload to __interceptor_memcpy
CVSS 6.5
CVE-2024-38949 MEDIUM
libde265 1.0.15 - Heap-based Buffer Overflow in display444as420 Function
CVSS 6.5
CVE-2024-23155 HIGH
Autodesk AutoCAD 2022-2022.1.5 - Heap-based Buffer Overflow via Malicious MODEL File
CVSS 7.8
CVE-2024-23154 HIGH
Autodesk AutoCAD 2022-2022.1.5 - Heap-based Buffer Overflow via SLDPRT File Parsing
CVSS 7.8
CVE-2024-37001 HIGH
Autodesk AutoCAD 2022-2022.1.5 - Heap-based Buffer Overflow via Crafted 3DM File
CVSS 7.8
CVE-2024-6154 MEDIUM
Parallels Desktop - Privilege Escalation
CVSS 6.7
CVE-2024-29013 MEDIUM
SonicOS < 7.0.1-5161 - Authenticated Denial of Service via memcpy Heap-based Buffer Overflow
CVSS 6.5
Details
Vulnerabilities 2,327
Exploit Likelihood High