CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,136 vulnerabilities with CWE-122
CVE-2023-50246 MEDIUM
JQ - Out-of-Bounds Write
CVSS 6.2
CVE-2023-35639 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20345 - Heap Buffer Overflow
CVSS 8.8
CVE-2023-35630 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20345 - Heap Buffer Overflow
CVSS 8.8
CVE-2023-21740 HIGH
Microsoft Windows Media - Remote Code Execution
CVSS 7.8
CVE-2023-28527 MEDIUM
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 6.2
CVE-2023-28526 MEDIUM
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 6.2
CVE-2023-28523 HIGH
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 8.4
CVE-2023-40465 HIGH
Sierrawireless Aleos < 4.16.0 - Out-of-Bounds Write
CVSS 8.3
CVE-2023-5908 CRITICAL
GE Industrial Gateway Server < 7.614 - Heap Buffer Overflow
CVSS 9.1
CVE-2023-41140 HIGH
Autodesk AutoCAD <2024 - Heap-Based Buffer Overflow
CVSS 7.8
CVE-2023-29073 CRITICAL
Autodesk AutoCAD <2024 - Heap-Based Buffer Overflow
CVSS 9.8
CVE-2023-47056 HIGH
Adobe Premiere Pro < 23.6 - Out-of-Bounds Write
CVSS 7.8
CVE-2023-47051 MEDIUM
Adobe Audition < 23.6.1 - Out-of-Bounds Write
CVSS 5.5
CVE-2023-47042 HIGH
Adobe Media Encoder < 23.6.0 - Out-of-Bounds Write
CVSS 7.8
CVE-2023-36425 HIGH
Windows DFS - RCE
CVSS 8.0
CVE-2023-36423 HIGH
Microsoft Remote Registry Service - RCE
CVSS 8.8
CVE-2023-36408 HIGH
Windows Hyper-V - Privilege Escalation
CVSS 7.8
CVE-2023-36402 HIGH
Microsoft WDAC OLE DB provider for SQL Server - RCE
CVSS 8.8
CVE-2023-36400 HIGH
Windows HMAC Key Derivation - Privilege Escalation
CVSS 8.8
CVE-2023-36042 MEDIUM
Visual Studio - DoS
CVSS 6.2
CVE-2023-36036 HIGH KEV
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2023-36028 CRITICAL
Microsoft PEAP - RCE
CVSS 9.8
CVE-2023-27882 CRITICAL
Silabs Gecko Software Development Kit - Out-of-Bounds Write
CVSS 9.0
CVE-2023-25181 CRITICAL
Silabs Gecko Software Development Kit - Out-of-Bounds Write
CVSS 9.0
CVE-2023-46256 MEDIUM
PX4-Autopilot <1.14.0-rc1 - Buffer Overflow
CVSS 4.4
Details
Vulnerabilities 2,136
Exploit Likelihood High