CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-44441 HIGH
GIMP < 2.10.36 - Remote Code Execution via DDS File Parsing
CVSS 7.8
CVE-2023-44429 HIGH
GStreamer < 1.22.7 - Remote Code Execution via AV1 Codec Parsing
CVSS 8.8
CVE-2023-44428 HIGH
MuseScore - Heap-based Buffer Overflow via CAP File Parsing
CVSS 7.8
CVE-2023-44418 HIGH
D-Link DIR-X3260 Firmware < 1.04b01 - Unauthenticated Heap-based Buffer Overflow via prog.cgi
CVSS 8.8
CVE-2023-42085 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in EMF File Parsing
CVSS 7.8
CVE-2023-42083 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in JPG File Parsing
CVSS 7.8
CVE-2023-42077 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in EMF File Parsing
CVSS 7.8
CVE-2023-42076 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in PDF File Parser
CVSS 7.8
CVE-2023-42039 HIGH
Kofax Power PDF < 5.0.0.12 - Remote Code Execution via PDF File Parsing
CVSS 7.8
CVE-2023-42038 HIGH
Kofax Power PDF < 5.0.0.12 - Remote Code Execution via PDF File Parsing
CVSS 7.8
CVE-2023-41229 HIGH
D-Link DIR-3040 < 1.20b03 - Unauthenticated Heap-Based Buffer Overflow via HNAP Referer Header
CVSS 8.8
CVE-2023-39494 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in OXPS File Parser
CVSS 7.8
CVE-2023-39492 HIGH
PDF-XChange Editor - Heap-based Buffer Overflow in PDF File Parser
CVSS 7.8
CVE-2023-38090 HIGH
Kofax Power PDF < 5.0.0.10 - Remote Code Execution via popUpMenu Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-38080 HIGH
Kofax Power PDF < 5.0.0.10 - Remote Code Execution via PDF File Parsing
CVSS 7.8
CVE-2023-37344 HIGH
Kofax Power PDF < 5.0.0.11 - Remote Code Execution via BMP File Parsing
CVSS 7.8
CVE-2023-37342 HIGH
Kofax Power PDF < 5.0.0.11 - Remote Code Execution via PNG File Parsing
CVSS 7.8
CVE-2023-37335 HIGH
Kofax Power PDF < 5.0.0.11 - Remote Code Execution via BMP File Parsing
CVSS 7.8
CVE-2023-37329 HIGH
GStreamer < 1.20.7 - Remote Code Execution via SRT Subtitle File Parsing
CVSS 8.8
CVE-2023-37328 HIGH
GStreamer < 1.20.7 - Remote Code Execution via PGS Subtitle File Parsing
CVSS 8.8
CVE-2023-35709 HIGH
Ashlar-Vellum Cobalt - Heap-based Buffer Overflow Remote Code Execution via CO File Parsing
CVSS 7.8
CVE-2023-34299 HIGH
Ashlar-Vellum Cobalt - Heap-based Buffer Overflow in CO File Parser
CVSS 7.8
CVE-2023-34289 HIGH
Ashlar-Vellum Cobalt < 12.0.1204.54 - Remote Code Execution via AR File Parsing
CVSS 7.8
CVE-2023-32157 HIGH
Tesla Model 3 Firmware - Heap-based Buffer Overflow via Bluetooth Pairing
CVSS 7.5
CVE-2023-32140 HIGH
D-Link DAP-1360 and DAP-2020 Firmware - Heap-based Buffer Overflow via webproc sys_Token Parameter
CVSS 7.5
Details
Vulnerabilities 2,327
Exploit Likelihood High