CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2022-24834 HIGH
Redis 2.6.0-6.0.19 - Authenticated Heap-based Buffer Overflow via Lua Script Execution
CVSS 7.0
CVE-2022-48512 CRITICAL
Huawei EMUI - Use-After-Free in Vdecoderservice
CVSS 9.8
CVE-2022-45115 HIGH
Ichitaro 2022 1.0.1.57600 - Heap-based Buffer Overflow in Attribute Arena
CVSS 7.8
CVE-2022-43648 HIGH
D-Link DIR-3040 < 1.20b03 - Unauthenticated Remote Code Execution via MiniDLNA Heap Overflow
CVSS 8.8
CVE-2022-43634 CRITICAL
Netatalk - Unauthenticated Remote Code Execution via dsi_writeinit Heap Overflow
CVSS 9.8
CVE-2022-2848 CRITICAL
Kepware KEPServerEX - Heap Buffer Overflow Remote Code Execution
CVSS 9.1
CVE-2022-24672 HIGH
Canon imageCLASS MF644Cdw 10.02 - RCE
CVSS 8.8
CVE-2022-42783 MEDIUM
Android - Heap-based Buffer Overflow in WLAN Driver
CVSS 5.5
CVE-2022-34454 MEDIUM
Dell PowerScale OneFS 9.1.0.0-9.1.0.19 - Authenticated Heap-based Buffer Overflow
CVSS 6.7
CVE-2022-45491 HIGH
json.h < 2022-11-14 - Heap-based Buffer Overflow in json_parse_value
CVSS 7.8
CVE-2022-34400 HIGH
Dell Alienware and Inspiron Firmware - Heap-based Buffer Overflow
CVSS 7.1
CVE-2022-41991 CRITICAL
Siretta QUARTZ-GOLD G5.0.1.5-210720-141020 - Heap-based Buffer Overflow via m2m DELETE_FILE Command
CVSS 9.8
CVE-2022-1892 MEDIUM
Lenovo Notebook Firmware - Buffer Overflow in SystemBootManagerDxe Driver
CVSS 6.7
CVE-2022-1891 MEDIUM
Lenovo ThinkBook and Yoga C640 Firmware - Buffer Overflow in SystemLoadDefaultDxe Driver
CVSS 6.7
CVE-2022-1890 MEDIUM
Lenovo ThinkBook and Yoga Firmware - Heap-based Buffer Overflow in ReadyBootDxe Driver
CVSS 6.7
CVE-2022-42405 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via EMF File Parsing
CVSS 7.8
CVE-2022-42403 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via PDF File Parsing
CVSS 7.8
CVE-2022-3160 HIGH
Siemens JT2Go < 14.1.0.5 and Teamcenter Visualization 13.3.0-13.3.0.8 - Heap-based Buffer Overflow via Crafted PDF File
CVSS 7.8
CVE-2022-43591 HIGH
Qt Project Qt <6.3.2 - Buffer Overflow
CVSS 8.8
CVE-2022-3437 MEDIUM
Samba 4.0.0-4.15.10 - Heap-based Buffer Overflow in GSSAPI DES/3DES Decryption
CVSS 6.5
CVE-2022-44430 MEDIUM
Android - Heap-based Buffer Overflow in WLAN Driver
CVSS 5.5
CVE-2022-44429 MEDIUM
Android - Heap-based Buffer Overflow in WLAN Driver
CVSS 5.5
CVE-2022-44428 MEDIUM
Android - Heap-based Buffer Overflow in WLAN Driver
CVSS 5.5
CVE-2022-44427 MEDIUM
Android - Heap-based Buffer Overflow in WLAN Driver
CVSS 5.5
CVE-2022-23547 MEDIUM
pjsip < 2.13.1 - Out-of-bounds Read in STUN Message Parser
CVSS 6.5
Details
Vulnerabilities 2,334
Exploit Likelihood High