CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-25664 HIGH
TensorFlow < 2.12.0 - Heap-based Buffer Overflow in TAvgPoolGrad
CVSS 7.5
CVE-2023-20081 MEDIUM
Cisco Adaptive Security Appliance Software - Denial of Service via DHCPv6 Message Validation
CVSS 6.8
CVE-2023-20029 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 4.4
CVE-2023-1570 LOW
syoyo tinydng - Heap-Based Buffer Overflow
CVSS 3.3
CVE-2023-1448 MEDIUM
GPAC 2.3-DEV-rev35-gbbca86917-master - Buffer Overflow
CVSS 5.3
CVE-2023-27585 HIGH
PJSIP < 2.13 - Heap-based Buffer Overflow in DNS Resolver Query Record Parsing
CVSS 7.5
CVE-2023-24913 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24907 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24876 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24868 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24867 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-23415 CRITICAL
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via ICMP
CVSS 9.8
CVE-2023-23406 HIGH
Microsoft Windows PostScript and PCL6 Class Printer Driver - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2023-23403 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - Remote Code Execution via Heap-based Buffer Overflow
CVSS 8.8
CVE-2023-23400 HIGH
Windows Server 2012, 2016, 2019, 2022 - Remote Code Execution via DNS Server Heap-based Buffer Overflow
CVSS 7.2
CVE-2023-1170 MEDIUM
vim < 9.0.1376 - Heap-based Buffer Overflow
CVSS 6.6
CVE-2023-1010 MEDIUM
vox2png 1.0 - Heap-based Buffer Overflow in vox2png.c
CVSS 5.3
CVE-2023-22236 HIGH
Adobe Animate < 22.0.8 and <= 23.0.0 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2023-0866 HIGH
gpac < 2.2.0 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-23782 HIGH
FortiWeb 6.2-6.2.6, 6.3.0-6.3.19, 6.4, 7.0.0-7.0.1 - Heap-based Buffer Overflow via Crafted Command Arguments
CVSS 7.8
CVE-2023-0841 MEDIUM
GPAC 2.3-DEV-rev40-g3602a5ded - Heap-based Buffer Overflow in mp3_dmx_process
CVSS 6.3
CVE-2023-23381 HIGH
Visual Studio 2017 15.0-15.9.51, 2019 16.0-16.11.23, 2022 17.0 - Remote Code Execution
CVSS 7.8
CVE-2023-23390 HIGH
3D Builder < 20.0.2.0 - Remote Code Execution
CVSS 7.8
CVE-2023-23378 HIGH
Print 3D < 3.3.791 - Remote Code Execution
CVSS 7.8
CVE-2023-23377 HIGH
3D Builder < 20.0.2.0 - Remote Code Execution
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High