CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-29162 HIGH
HDF5 < 1.14.3 - Heap-based Buffer Overflow in H5HG_read
CVSS 7.4
CVE-2024-29161 HIGH
HDF5 < 1.14.4 - Heap-based Buffer Overflow in H5A__attr_release_table
CVSS 8.8
CVE-2024-29160 HIGH
HDF5 < 1.14.4 - Heap-based Buffer Overflow in H5HG__cache_heap_deserialize
CVSS 7.4
CVE-2024-29158 HIGH
HDF5 < 1.14.3 - Heap-based Buffer Overflow in H5FL_arr_malloc
CVSS 7.4
CVE-2024-29157 CRITICAL
HDF5 < 1.14.3 - Heap-based Buffer Overflow in H5HG_read
CVSS 9.8
CVE-2024-4559 MEDIUM
Google Chrome < 124.0.6367.155 - Heap-based Buffer Overflow in WebAudio
CVSS 6.5
CVE-2024-32664 MEDIUM
Suricata 6.0.0-6.0.18 - Heap-based Buffer Overflow via base64_decode with bytes Option
CVSS 5.3
CVE-2024-3758 MEDIUM
OpenHarmony < 4.0.1 - Heap-based Buffer Overflow
CVSS 6.5
CVE-2024-34250 MEDIUM
Bytecode Alliance wasm-micro-runtime <2.0.0 - Buffer Overflow
CVSS 6.2
CVE-2024-34249 CRITICAL
wasm3 v0.5.0 - Heap-based Buffer Overflow via DeallocateSlot Function
CVSS 9.8
CVE-2024-34408 MEDIUM
Tencent libpag <4.3.51 - Buffer Overflow
CVSS 5.3
CVE-2024-33429 HIGH
phiola v2.0-rc22 - Heap-based Buffer Overflow in pcm_convert.h
CVSS 7.1
CVE-2024-33428 HIGH
stsaz phiola v2.0-rc22 - Heap-based Buffer Overflow via Crafted WAV File
CVSS 8.8
CVE-2024-25048 HIGH
IBM MQ Appliance <9.3 - Buffer Overflow
CVSS 7.5
CVE-2024-31036 MEDIUM
NanoMQ 0.21.7 - Heap-based Buffer Overflow via Crafted Hexstreams
CVSS 6.8
CVE-2024-32038 CRITICAL
Wazuh Manager <4.7.2 - Buffer Overflow
CVSS 9.8
CVE-2024-29204 CRITICAL
Ivanti Avalanche <6.4.3 - Buffer Overflow
CVSS 9.8
CVE-2024-24996 CRITICAL
Ivanti Avalanche <6.4.3 - Buffer Overflow
CVSS 9.8
CVE-2024-0257 LOW
RoboDK 5.5.4 - Heap-based Buffer Overflow via Project File Processing
CVSS 3.3
CVE-2024-31582 HIGH
FFmpeg 6.1 - Heap-based Buffer Overflow in draw_block_rectangle
CVSS 7.8
CVE-2024-31580 MEDIUM
PyTorch < 2.2.0 - Heap-based Buffer Overflow in Vararg Functions
CVSS 4.0
CVE-2024-3516 MEDIUM
Google Chrome <123.0.6312.122 - Buffer Overflow
CVSS 6.5
CVE-2024-25115 HIGH
RedisBloom 2.0.0-2.4.6 and 2.5.0-2.6.9 - Authenticated Heap Overflow via CF.LOADCHUNK Command
CVSS 7.0
CVE-2024-29985 HIGH
Microsoft OLE DB Driver for SQL Server - RCE
CVSS 8.8
CVE-2024-29984 HIGH
Microsoft OLE DB Driver for SQL Server - RCE
CVSS 8.8
Details
Vulnerabilities 2,327
Exploit Likelihood High