CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2023-21587 HIGH
Adobe InDesign <= 17.4 and 18.0 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2023-0288 HIGH
vim/vim <9.0.1189 - Buffer Overflow
CVSS 7.8
CVE-2023-21793 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21792 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21791 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21790 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21787 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21786 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21785 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21783 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21782 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21781 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21780 HIGH
3D Builder < 20.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-21738 HIGH
Microsoft Office Visio - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-21737 HIGH
Microsoft Visio - Remote Code Execution via Heap-based Buffer Overflow
CVSS 7.8
CVE-2023-21733 HIGH
Windows Bind Filter Driver - Privilege Escalation
CVSS 7.0
CVE-2023-21560 MEDIUM
Windows Boot Manager - Privilege Escalation
CVSS 6.6
CVE-2023-0051 HIGH
vim/vim <9.0.1144 - Buffer Overflow
CVSS 7.8
CVE-2022-39068 MEDIUM
ZTE MF296R Firmware - Authenticated Denial of Service via SMS Parameter Buffer Overflow
CVSS 4.5
CVE-2022-43655 HIGH
Bentley View - Heap-based Buffer Overflow via FBX File Parsing
CVSS 7.8
CVE-2022-23086 HIGH
FreeBSD 12.0-12.2 - Heap-based Buffer Overflow in mpr/mps/mpt Driver ioctl Handlers
CVSS 7.8
CVE-2022-36764 HIGH
EDK2 < 202311 - Heap Buffer Overflow in Tcg2MeasurePeImage()
CVSS 7.0
CVE-2022-36763 HIGH
EDK2 < 202311 - Heap Buffer Overflow in Tcg2MeasureGptTable
CVSS 7.0
CVE-2022-46290 CRITICAL
Open Babel 3.1.1 - Heap-based Buffer Overflow in ORCA Format nAtoms Functionality
CVSS 9.8
CVE-2022-46289 CRITICAL
Open Babel 3.1.1 and master commit 530dbfa3 - Heap-based Buffer Overflow in ORCA Format nAtoms Functionality
CVSS 9.8
Details
Vulnerabilities 2,334
Exploit Likelihood High