CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,327 vulnerabilities with CWE-122
CVE-2023-23376 HIGH KEV
Windows Common Log File System Driver - Elevation of Privilege via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-21812 HIGH
Windows Common Log File System Driver - Privilege Escalation
CVSS 7.8
CVE-2023-21804 HIGH
Windows Graphics Component - Privilege Escalation
CVSS 7.8
CVE-2023-21799 HIGH
Microsoft WDAC OLE DB provider for SQL Server - RCE
CVSS 8.8
CVE-2023-21695 HIGH
Windows 10, 11, Server 2008-2022 - Remote Code Execution via PEAP Heap-based Buffer Overflow
CVSS 7.5
CVE-2023-21694 MEDIUM
Windows Fax Service - Remote Code Execution
CVSS 6.8
CVE-2023-21692 CRITICAL
Windows 10 1507-21H2 - Remote Code Execution via PEAP Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-21690 CRITICAL
Windows 10 1507-21H2 - Remote Code Execution via PEAP Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-21689 CRITICAL
Windows 10 - Remote Code Execution via PEAP Heap-based Buffer Overflow
CVSS 9.8
CVE-2023-21528 HIGH
Microsoft SQL Server - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-24551 HIGH
Solid Edge <V222.0MP12, <V223.0Update2 - Code Injection
CVSS 7.8
CVE-2023-24550 HIGH
Solid Edge <V222.0MP12-V223.0Update2 - Code Injection
CVSS 7.8
CVE-2023-0819 HIGH
gpac < 2.3.0-dev - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-0760 HIGH
gpac < 2.2.0 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-23582 MEDIUM
Snap One Wattbox WB-300-IP-3 Firmware <= wb10.9a17 - Heap-based Buffer Overflow
CVSS 5.3
CVE-2023-0433 HIGH
vim < 9.0.1225 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-21605 HIGH
Adobe Acrobat Reader <22.003.20282 - RCE
CVSS 7.8
CVE-2023-21594 HIGH
Adobe InCopy <18.0, 17.4 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-21587 HIGH
Adobe InDesign <= 17.4 and 18.0 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2023-0288 HIGH
vim/vim <9.0.1189 - Buffer Overflow
CVSS 7.8
CVE-2023-21793 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21792 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21791 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21790 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21787 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
Details
Vulnerabilities 2,327
Exploit Likelihood High