CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-37246 HIGH
Siemens Tecnomatix Plant Simulation Heap-based Buffer Overflow via PRT File Parsing
CVSS 7.8
CVE-2023-34432 HIGH
sound_exchange < 14.4.3 - Heap-based Buffer Overflow in lsx_readbuf Function
CVSS 7.8
CVE-2023-34318 HIGH
sound_exchange - Heap-based Buffer Overflow in startread Function
CVSS 7.8
CVE-2023-27390 HIGH
Diagon 1.0.139 - Heap-based Buffer Overflow in Sequence::DrawText
CVSS 7.8
CVE-2023-34474 MEDIUM
ImageMagick < 7.1.1-10 - Heap-based Buffer Overflow in ReadTIM2ImageData
CVSS 5.5
CVE-2023-3291 LOW
gpac < 2.2.2 - Heap-based Buffer Overflow
CVSS 3.3
CVE-2023-32028 HIGH
Microsoft OLE DB Driver for SQL Server 18.0.2-18.6.0006.0 - Remote Code Execution
CVSS 7.8
CVE-2023-32027 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-32026 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-32025 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-24897 HIGH
Microsoft .NET and .NET Framework - Remote Code Execution
CVSS 7.8
CVE-2023-33146 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-33133 HIGH
Microsoft Excel - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-33129 MEDIUM
Microsoft SharePoint Server - Denial of Service via Heap-based Buffer Overflow
CVSS 6.5
CVE-2023-29372 HIGH
Microsoft WDAC OLE DB provider for SQL Server - RCE
CVSS 8.8
CVE-2023-29370 HIGH
Microsoft Windows Media - Remote Code Execution
CVSS 7.8
CVE-2023-29363 CRITICAL
Microsoft Windows Pragmatic General Multicast - Remote Code Execution
CVSS 9.8
CVE-2023-29362 HIGH
Remote Desktop Client < 1.2.4337 - Remote Code Execution
CVSS 8.8
CVE-2023-27997 CRITICAL KEV
FortiOS/FortiProxy SSL-VPN Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-34488 HIGH
NanoMQ 0.17.5 - Heap-based Buffer Overflow in MQTT Parser
CVSS 7.8
CVE-2023-24014 HIGH
Delta Electronics' CNCSoft-B DOPSoft <1.0.0.4 - Buffer Overflow
CVSS 7.8
CVE-2023-0667 MEDIUM
Wireshark < 4.0.6 - Heap-based Buffer Overflow via MSMMS Packet
CVSS 6.5
CVE-2023-0666 MEDIUM
Wireshark < 4.0.6 - Heap-based Buffer Overflow via RTPS Packet Length Validation
CVSS 6.5
CVE-2023-2157 MEDIUM
ImageMagick < 7.1.1-9 - Heap-based Buffer Overflow
CVSS 5.5
CVE-2023-29344 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High