CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-32324 HIGH
OpenPrinting CUPS < 2.4.2 - Denial of Service via Heap Buffer Overflow in format_log_line
CVSS 7.5
CVE-2023-32307 HIGH
sofia-sip < 1.13.15 - Integer Overflow in STUN Packet Attribute Parsing
CVSS 7.5
CVE-2023-2804 MEDIUM
libjpeg-turbo - Heap-based Buffer Overflow in h2v2_merged_upsample_internal
CVSS 6.5
CVE-2023-30763 HIGH
Intel SoC Watch < 2021.1 - Heap-based Buffer Overflow
CVSS 7.2
CVE-2023-29283 HIGH
Adobe Substance 3D Painter <8.3.0 - RCE
CVSS 7.8
CVE-2023-0854 CRITICAL
Canon MF/LBP Series Firmware < 11.04 - Heap-based Buffer Overflow via NetBIOS QNAME Processing
CVSS 9.8
CVE-2023-0851 CRITICAL
Canon Office/Small Office Multifunction & Laser Printers < 11.04 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-29341 HIGH
AV1 Video Extension < 1.1.51091.0 - Remote Code Execution
CVSS 7.8
CVE-2023-24948 HIGH
Windows Bluetooth Driver - Privilege Escalation
CVSS 7.4
CVE-2023-24943 CRITICAL
Microsoft Windows Pragmatic General Multicast - Remote Code Execution
CVSS 9.8
CVE-2023-27410 LOW
SCALANCE LPE9403 < 2.1 - Authenticated Denial of Service via Backup Password Overflow
CVSS 2.7
CVE-2023-2241 MEDIUM
PoDoFo 0.10.0 - Heap-Based Buffer Overflow in PdfXRefStreamParserObject.cpp
CVSS 5.3
CVE-2023-27911 HIGH
Autodesk FBX SDK 2020.0-2020.3.3 - Heap-based Buffer Overflow via Malicious FBX File
CVSS 7.8
CVE-2023-26416 HIGH
Adobe Substance 3D Designer <12.4.0 - RCE
CVSS 7.8
CVE-2023-26413 HIGH
Adobe Substance 3D Designer <12.4.0 - RCE
CVSS 7.8
CVE-2023-26394 HIGH
Adobe Substance 3D Stager <2.0.1 - Code Injection
CVSS 7.8
CVE-2023-1906 MEDIUM
ImageMagick < 6.9.12-84 - Denial of Service via Heap-based Buffer Overflow in ImportMultiSpectralQuantum
CVSS 5.5
CVE-2023-28311 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-28292 HIGH
Raw Image Extension < 2.1.60611.0 - Remote Code Execution
CVSS 7.8
CVE-2023-28275 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via WDAC OLE DB Provider
CVSS 8.8
CVE-2023-28269 MEDIUM
Windows Boot Manager - Security Feature Bypass via Heap-based Buffer Overflow
CVSS 6.2
CVE-2023-28262 HIGH
Visual Studio 2019 16.0-16.11.25 and 2022 < 17.0.21 - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-28254 HIGH
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Heap-based Buffer Overflow
CVSS 7.2
CVE-2023-28252 HIGH KEV
Windows Common Log File System Driver - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-28240 HIGH
Windows Server 2008, 2012, 2016, 2019, 2022 - Remote Code Execution via Network Load Balancing Heap Overflow
CVSS 8.8
Details
Vulnerabilities 2,327
Exploit Likelihood High