CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-37080 CRITICAL
VMware vCenter Server - Heap-based Buffer Overflow via DCERPC Protocol
CVSS 9.8
CVE-2024-37280 MEDIUM
Elasticsearch 8.13.1-8.13.9 - Denial of Service via Passthrough Field Mapping
CVSS 4.9
CVE-2024-5835 HIGH
Google Chrome < 126.0.6478.54 - Heap-based Buffer Overflow in Tab Groups
CVSS 8.8
CVE-2024-36702 HIGH
libiec61850 v1.5 - Heap-based Buffer Overflow via BerEncoder_encodeLength
CVSS 7.4
CVE-2024-30095 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 7.8
CVE-2024-30094 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 7.8
CVE-2024-30091 HIGH
Windows 10/11, Server 2008-2022 Elevation of Privilege via Win32k Heap Overflow
CVSS 7.8
CVE-2024-30085 HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2024-30077 HIGH
Windows OLE - Remote Code Execution
CVSS 8.0
CVE-2024-30075 HIGH
Windows Link Layer Topology Discovery Protocol - Remote Code Execution
CVSS 8.0
CVE-2024-30074 HIGH
Windows Link Layer Topology Discovery Protocol - Remote Code Execution
CVSS 8.0
CVE-2024-30066 MEDIUM
Windows 10/11, Server 2012-2022 Elevation of Privilege via Winlogon Heap Overflow
CVSS 5.5
CVE-2024-2011 HIGH
HitachiEnergy FOXMAN-UN/UNEM - Heap-based Buffer Overflow
CVSS 8.6
CVE-2024-5301 HIGH
Kofax Power PDF < 5.0.0.18 - Remote Code Execution via PSD File Parsing
CVSS 7.8
CVE-2024-27374 MEDIUM
Samsung Mobile Processor - Memory Corruption
CVSS 6.7
CVE-2024-27372 MEDIUM
Samsung Mobile Processor - Memory Corruption
CVSS 6.7
CVE-2024-36843 HIGH
libmodbus 3.1.6 - Heap-based Buffer Overflow in modbus_mapping_free()
CVSS 7.5
CVE-2024-22058 HIGH
Ivanti EPM <2021.1 - Buffer Overflow
CVSS 7.8
CVE-2024-5493 HIGH
Google Chrome < 125.0.6422.141 - Heap-based Buffer Overflow in WebRTC
CVSS 8.8
CVE-2024-35434 HIGH
Irontec Sngrep v1.8.1 - Heap-based Buffer Overflow in rtp_check_packet
CVSS 7.5
CVE-2024-5228 HIGH
TP-Link Omada ER605 - Unauthenticated Heap-based Buffer Overflow via Comexe DDNS Response Handling
CVSS 7.5
CVE-2024-5160 HIGH
Google Chrome <125.0.6422.76 - Buffer Overflow
CVSS 8.8
CVE-2024-4323 CRITICAL
Fluent Bit 2.0.7-3.0.3 - Heap-based Buffer Overflow in HTTP Server Trace Request Parsing
CVSS 9.8
CVE-2024-30288 HIGH
Adobe Framemaker < 2020.6 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2024-30294 HIGH
Adobe Animate < 23.0.6 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High