CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2024-25448 HIGH
imlib2 1.9.1 - Heap-based Buffer Overflow via Crafted Image Parsing
CVSS 8.8
CVE-2024-1283 CRITICAL
Google Chrome <121.0.6167.160 - Buffer Overflow
CVSS 9.8
CVE-2024-24577 HIGH
libgit2 <1.6.5 and <1.7.2 - Code Execution via git_index_add Heap Corruption
CVSS 8.6
CVE-2024-0911 MEDIUM
GNU indent - Heap-based Buffer Overflow via Crafted File
CVSS 5.5
CVE-2024-0684 MEDIUM
GNU coreutils - Heap-based Buffer Overflow in split line_bytes_split()
CVSS 5.5
CVE-2024-22211 LOW
FreeRDP < 2.11.5 - Heap-Buffer Overflow via RDPGFX_RESET_GRAPHICS_PDU
CVSS 3.7
CVE-2024-21596 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via BGP UPDATE Message
CVSS 5.3
CVE-2024-21594 MEDIUM
Juniper Junos OS Authenticated DoS via NSD Command Execution
CVSS 5.5
CVE-2024-21337 MEDIUM
Microsoft Edge Chromium < 120.0.2210.133 - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 5.2
CVE-2024-20697 HIGH
Microsoft Windows libarchive - Remote Code Execution
CVSS 7.3
CVE-2024-20696 HIGH
Microsoft Windows libarchive - Remote Code Execution
CVSS 7.3
CVE-2024-20677 HIGH
Microsoft Office FBX File Support - Remote Code Execution
CVSS 7.8
CVE-2023-43688 HIGH
Malwarebytes 4.x-5.x and Nebula 2020-10-21 and later - Heap-based Buffer Overflow in Buffer Encryption Utilities
CVSS 7.5
CVE-2023-28905 HIGH
Volkswagen MIB3 infotainment system MIB3 OI MQB <0304 - Remote Code Execution via Image Processing Heap Overflow
CVSS 8.0
CVE-2023-31276 HIGH
Intel Server Board <02.01.0017 - Buffer Overflow
CVSS 8.2
CVE-2023-40222 HIGH
Ashlar-Vellum Cobalt < 12.4.1204.200 - Heap-based Buffer Overflow via CO File Parsing
CVSS 7.8
CVE-2023-50739 HIGH
Lexmark Printer Firmware < 230.209 - Remote Code Execution via IPP Buffer Overflow
CVSS 8.8
CVE-2023-29125 CRITICAL
Enelx Waybox Pro Firmware <= 2.1.1.0_jb3vu096a - Heap Buffer Overflow
CVSS 9.0
CVE-2023-52168 HIGH
7-Zip < 24.01 - Heap-based Buffer Overflow in NTFS Handler
CVSS 8.4
CVE-2023-49600 HIGH
libigl 2.5.0 - Heap-based Buffer Overflow via PlyFile ply_cast_ascii
CVSS 8.1
CVE-2023-6349 HIGH
libvpx < 1.13.1 - Heap-based Buffer Overflow via VP9 Frame Encoding
CVSS 7.5
CVE-2023-51596 HIGH
BlueZ PBAP - Remote Code Execution via Heap Buffer Overflow
CVSS 7.1
CVE-2023-50230 HIGH
BlueZ 5.66-5.70 - Heap-based Buffer Overflow in Phone Book Access Profile
CVSS 8.0
CVE-2023-50229 HIGH
BlueZ 5.66-5.69 - Heap-based Buffer Overflow in Phone Book Access Profile
CVSS 8.0
CVE-2023-44442 HIGH
GIMP < 2.10.36 - Remote Code Execution via PSD File Parsing Heap-based Buffer Overflow
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High