CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-32138 HIGH
D-Link DAP-1360 <6.15eub01 & DAP-2020 <1.03rc004 - Unauthenticated Heap Overflow via /cgi-bin/webproc
CVSS 8.8
CVE-2023-28798 MEDIUM
Zscaler Client Connector - Heap Write - RCE
CVSS 6.5
CVE-2023-26793 CRITICAL
libmodbus <3.1.10 - Buffer Overflow
CVSS 9.8
CVE-2023-51794 HIGH
Ffmpeg <N113007-g8d24a28d06 - Buffer Overflow
CVSS 7.8
CVE-2023-50364 MEDIUM
QNAP QTS and QuTS hero - Authenticated Remote Code Execution via Heap-based Buffer Overflow
CVSS 6.4
CVE-2023-51795 HIGH
Ffmpeg <N113007-g8d24a28d06 - Buffer Overflow
CVSS 8.0
CVE-2023-50009 HIGH
FFmpeg 6.1-3-g466799d4f5 - Heap-based Buffer Overflow in ff_gaussian_blur_8
CVSS 8.0
CVE-2023-49501 HIGH
FFmpeg v.n6.1-3-g466799d4f5 - Heap-based Buffer Overflow in config_eq_output Function
CVSS 8.0
CVE-2023-5404 HIGH
Honeywell Experion Server - Remote Code Execution via Malformed Message Pointer Overwrite
CVSS 8.1
CVE-2023-5400 HIGH
Honeywell Experion Server - Heap-based Buffer Overflow via Malformed Message
CVSS 8.1
CVE-2023-49528 HIGH
FFmpeg n6.1-3-g466799d4f5 - Heap-based Buffer Overflow in de_stereo Component
CVSS 8.0
CVE-2023-46426 HIGH
gpac 2.3-DEV-rev588-g7edc40fee-master - Heap-based Buffer Overflow in gf_fwrite
CVSS 8.8
CVE-2023-45591 HIGH
AiLux imx6 < 1.0.7-2 - Authenticated Heap-based Buffer Overflow in logger_generic Function
CVSS 7.5
CVE-2023-42848 HIGH
iPadOS < 16.7.2 - Heap-based Buffer Overflow via Maliciously Crafted Image
CVSS 7.8
CVE-2023-45318 CRITICAL
Silabs Gecko Software Development Kit - Out-of-Bounds Write
CVSS 10.0
CVE-2023-41276 MEDIUM
QNAP QTS, QuTS hero, and QuTScloud - Authenticated Heap-based Buffer Overflow
CVSS 5.5
CVE-2023-41275 MEDIUM
QNAP QTS, QuTS hero, and QuTScloud - Authenticated Heap-based Buffer Overflow
CVSS 5.5
CVE-2023-41273 MEDIUM
QNAP QTS, QuTS hero, and QuTScloud - Authenticated Remote Code Execution via Heap-based Buffer Overflow
CVSS 5.5
CVE-2023-5841 CRITICAL
OpenEXR < 3.2.1 - Heap-based Buffer Overflow in Deep Scanline Data Parsing
CVSS 9.1
CVE-2023-6779 HIGH
glibc 2.37-2.38 - Heap-based Buffer Overflow in __vsyslog_internal
CVSS 8.2
CVE-2023-6246 HIGH
glibc >=2.36 - Heap-based Buffer Overflow in __vsyslog_internal
CVSS 8.4
CVE-2023-52356 HIGH
libtiff - Heap-based Buffer Overflow via TIFFReadRGBATileExt()
CVSS 7.5
CVE-2023-31031 MEDIUM
NVIDIA DGX Station - Buffer Overflow
CVSS 4.2
CVE-2023-48263 HIGH
Bosch nexo-os 1000-1500-sp2 - Heap-based Buffer Overflow via Crafted Network Request
CVSS 8.1
CVE-2023-37297 HIGH
AMI MegaRAC SP-X 12-12.6 - Heap-based Buffer Overflow via Adjacent Network
CVSS 8.3
Details
Vulnerabilities 2,327
Exploit Likelihood High