CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2022-43602 HIGH
OpenImageIO Project OpenImageIO <2.4.4.2 - RCE
CVSS 8.1
CVE-2022-43601 HIGH
OpenImageIO Project OpenImageIO <2.4.4.2 - RCE
CVSS 8.1
CVE-2022-43600 HIGH
OpenImageIO Project OpenImageIO <2.4.4.2 - Code Injection
CVSS 8.1
CVE-2022-43599 HIGH
OpenImageIO Project OpenImageIO <2.4.4.2 - RCE
CVSS 8.1
CVE-2022-43598 HIGH
OpenImageIO Project OpenImageIO <v2.4.4.2 - Memory Corruption
CVSS 8.1
CVE-2022-43597 HIGH
OpenImageIO Project OpenImageIO <v2.4.4.2 - Memory Corruption
CVSS 8.1
CVE-2022-41838 CRITICAL
OpenImageIO <v2.4.4.2 - Buffer Overflow
CVSS 9.8
CVE-2022-41794 CRITICAL
OpenImageIO <2.3.19.0 - Buffer Overflow
CVSS 9.8
CVE-2022-41639 CRITICAL
OpenImageIO master-branch-9aeece7a/v2.3.19.0 - Buffer Overflow
CVSS 9.8
CVE-2022-23537 MEDIUM
PJSIP < 2.13.1 - Out-of-bounds Read via STUN Message Parsing
CVSS 6.5
CVE-2022-4584 MEDIUM
Axiomatic Bento4 <1.6.0-639 - Buffer Overflow
CVSS 6.3
CVE-2022-2601 HIGH
GRUB2 < 2.06 - Heap-based Buffer Overflow via Crafted PF2 Font
CVSS 8.6
CVE-2022-44910 HIGH
Binbloom 2.0 - Heap-based Buffer Overflow via read_pointer Function
CVSS 7.8
CVE-2022-44654 HIGH
Trend Micro Apex One - Heap-based Buffer Overflow in Monitor Engine
CVSS 7.5
CVE-2022-2948 HIGH
GE Cimplicity < 2022 - Heap Buffer Overflow
CVSS 7.8
CVE-2022-3491 HIGH
vim < 9.0.0742 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2022-3520 CRITICAL
vim/vim <9.0.0765 - Buffer Overflow
CVSS 9.8
CVE-2022-4141 HIGH
vim < 9.0.0946 - Heap-based Buffer Overflow via CTRL-W gf in Substitute Command
CVSS 7.8
CVE-2022-43171 MEDIUM
LIEF < 0.12.3 - Denial of Service via Crafted MachO File
CVSS 6.5
CVE-2022-24942 CRITICAL
Micrium uC-HTTP 3.01.01 - Remote Code Execution via HTTP Request
CVSS 9.1
CVE-2022-20946 HIGH
Cisco Firepower Threat Defense 6.3.0-6.3.0.4 - Unauthenticated Denial of Service via GRE Tunnel Decapsulation
CVSS 8.6
CVE-2022-45188 HIGH
netatalk <= 3.1.13 - Heap-based Buffer Overflow via Crafted .appl File
CVSS 7.8
CVE-2022-39136 HIGH
Siemens JT2Go < 14.1.0.4 and Teamcenter Visualization < 13.3.0.7 - Heap-based Buffer Overflow via TIF File Parsing
CVSS 7.8
CVE-2022-2809 HIGH
OpenBMC 2.10.0-2.12.9 - Denial of Service via Multipart Parser Heap Overflow
CVSS 8.2
CVE-2022-2069 HIGH
Siemens JT2Go < 13.3.0.5 and Teamcenter Visualization < 14.0.0.2 - Heap-based Buffer Overflow in APDFL.dll
CVSS 7.8
Details
Vulnerabilities 2,334
Exploit Likelihood High