CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-37295 HIGH
AMI MegaRAC SP-X 12-12.7 - Heap-based Buffer Overflow via Adjacent Network
CVSS 8.3
CVE-2023-37294 HIGH
AMI MegaRAC SP-X 12-12.7 - Heap-based Buffer Overflow via Adjacent Network
CVSS 8.3
CVE-2023-49123 HIGH
Solid Edge SE2023 <V223.0 Update 10 - Buffer Overflow
CVSS 7.8
CVE-2023-49122 HIGH
Solid Edge SE2023 <V223.0 Update 10 - Buffer Overflow
CVSS 7.8
CVE-2023-49121 HIGH
Solid Edge SE2023 <V223.0 Update 10 - Buffer Overflow
CVSS 7.8
CVE-2023-6992 MEDIUM
Cloudflare zlib < 2023-11-16 - Denial of Service via Deflation Algorithm Memory Corruption
CVSS 4.0
CVE-2023-47039 HIGH
Perl < 5.32.1 - Heap-based Buffer Overflow via Path Search Order Issue
CVSS 7.8
CVE-2023-7104 MEDIUM
SQLite < 3.43.0 - Heap-Based Buffer Overflow in sessionReadRecord
CVSS 5.5
CVE-2023-7158 HIGH
MicroPython < 1.22.0 - Heap-based Buffer Overflow in slice_indices Function
CVSS 7.3
CVE-2023-48704 HIGH
ClickHouse 23.3-23.3.18.15 & Cloud < 23.9.2.47551 - Heap Overflow via Gorilla Decompression
CVSS 7.0
CVE-2023-47118 HIGH
ClickHouse 23.3-23.3.16.7, 23.9-23.9.4.11, and Cloud < 23.9.2.47475 - Heap-based Buffer Overflow via T64 Codec
CVSS 7.0
CVE-2023-47038 HIGH
perl 5.30.0-5.38.0 - Heap-based Buffer Overflow via Crafted Regular Expression
CVSS 7.0
CVE-2023-3430 HIGH
OpenImageIO - Heap-based Buffer Overflow in GIF Image Input Handler
CVSS 7.5
CVE-2023-33221 MEDIUM
IDEMIA Biometric Device Firmware DESFire - Heap Buffer Overflow Code Execution
CVSS 6.8
CVE-2023-50246 MEDIUM
JQ - Out-of-Bounds Write
CVSS 6.2
CVE-2023-35639 HIGH
Microsoft ODBC Driver - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2023-35630 HIGH
Windows 10/11, Server 2008-2022 - Remote Code Execution via Internet Connection Sharing
CVSS 8.8
CVE-2023-21740 HIGH
Microsoft Windows Media - Remote Code Execution
CVSS 7.8
CVE-2023-28527 MEDIUM
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 6.2
CVE-2023-28526 MEDIUM
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 6.2
CVE-2023-28523 HIGH
IBM Informix Dynamic Server <14.10 - Buffer Overflow
CVSS 8.4
CVE-2023-40465 HIGH
Sierra Wireless ALEOS < 4.16.0 - Denial of Service via Captive Portal
CVSS 8.3
CVE-2023-5908 CRITICAL
KEPServerEX < 6.14.263.0 - Buffer Overflow
CVSS 9.1
CVE-2023-41140 HIGH
Autodesk AutoCAD <2024 - Heap-Based Buffer Overflow
CVSS 7.8
CVE-2023-29073 CRITICAL
Autodesk AutoCAD <2024 - Heap-Based Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 2,327
Exploit Likelihood High