CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-47056 HIGH
Adobe Premiere Pro < 23.6 and 24.0 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-47051 MEDIUM
Adobe Audition <= 24.0 and <= 23.6.1 - Heap-based Buffer Overflow
CVSS 5.5
CVE-2023-47042 HIGH
Adobe Media Encoder < 23.6.0 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2023-36425 HIGH
Microsoft Windows DFS - Remote Code Execution
CVSS 8.0
CVE-2023-36423 HIGH
Microsoft Remote Registry Service - RCE
CVSS 8.8
CVE-2023-36408 HIGH
Windows Hyper-V - Privilege Escalation
CVSS 7.8
CVE-2023-36402 HIGH
Microsoft WDAC OLE DB provider for SQL Server - RCE
CVSS 8.8
CVE-2023-36400 HIGH
Windows HMAC Key Derivation - Privilege Escalation
CVSS 8.8
CVE-2023-36042 MEDIUM
Visual Studio 2019 16.0-16.11.32 and 2022 17.2-17.2.22 - Denial of Service
CVSS 6.2
CVE-2023-36036 HIGH KEV
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2023-36028 CRITICAL
Windows 10 - Remote Code Execution via PEAP Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-27882 CRITICAL
Silabs Gecko Software Development Kit - Out-of-Bounds Write
CVSS 9.0
CVE-2023-25181 CRITICAL
Silabs Gecko Software Development Kit - Out-of-Bounds Write
CVSS 9.0
CVE-2023-46256 MEDIUM
PX4-Autopilot <1.14.0-rc1 - Buffer Overflow
CVSS 4.4
CVE-2023-5568 MEDIUM
Samba < 4.19.2 - Authenticated Heap-based Buffer Overflow
CVSS 5.9
CVE-2023-4692 HIGH
GRUB2 < 2.12 - Heap-based Buffer Overflow in NTFS Filesystem Driver
CVSS 7.5
CVE-2023-5686 HIGH
radare2 < 5.9.0 - Heap-based Buffer Overflow
CVSS 8.8
CVE-2023-27395 CRITICAL
SoftEther VPN 4.41-9782-beta, 5.01.9674, 5.02 - Heap-based Buffer Overflow in WpcParsePacket
CVSS 9.0
CVE-2023-36730 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-36598 HIGH
Windows 10/11 WDAC ODBC Driver Heap-based Buffer Overflow RCE
CVSS 7.8
CVE-2023-36577 HIGH
Microsoft WDAC OLE DB provider for SQL Server - RCE
CVSS 8.8
CVE-2023-36417 HIGH
Microsoft OLE DB Driver for SQL Server 18.0.0-18.6.0007.0 - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-43787 HIGH
libX11 < 1.8.7 - Integer Overflow in XCreateImage()
CVSS 7.8
CVE-2023-5460 LOW
Delta Electronics WPLSoft < 2.51 - Heap-based Buffer Overflow in Modbus Data Packet Handler
CVSS 3.5
CVE-2023-3428 MEDIUM
ImageMagick < 7.1.1-19 - Heap-based Buffer Overflow in TIFF Coder
CVSS 6.2
Details
Vulnerabilities 2,327
Exploit Likelihood High