CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2022-39260 HIGH
Git < 2.30.6 - Remote Code Execution via Git Shell Argument Array Overflow
CVSS 8.5
CVE-2022-35712 CRITICAL
Adobe ColdFusion <Update 14 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2022-35711 CRITICAL
Adobe ColdFusion <Update 14 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2022-37864 HIGH
Siemens Solid Edge < SE2022MP9 - Heap-based Buffer Overflow via DWG File Parsing
CVSS 7.8
CVE-2022-39852 HIGH
Android - Heap-based Buffer Overflow in libagifencoder.quram.so makeContactAGIF
CVSS 8.0
CVE-2022-38742 HIGH
Rockwell Automation ThinManager ThinServer <13.0.0 - Buffer Overflow
CVSS 8.1
CVE-2022-2347 HIGH
U-Boot 2012.10-2022.07 - Heap-based Buffer Overflow via USB DFU Download Setup Packet
CVSS 7.7
CVE-2022-2566 CRITICAL
FFMPEG <5.1 - Remote Code Execution
CVSS 9.0
CVE-2022-36934 CRITICAL
WhatsApp < 2.22.16.12 - Remote Code Execution via Integer Overflow in Video Call
CVSS 9.8
CVE-2022-35708 HIGH
Adobe Bridge < 11.1.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2022-35706 HIGH
Adobe Bridge < 11.1.4 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2022-3234 HIGH
vim/vim <9.0.0483 - Buffer Overflow
CVSS 7.8
CVE-2022-38433 HIGH
Adobe Photoshop <22.5.8, 23.4.2 - RCE
CVSS 7.8
CVE-2022-38432 HIGH
Adobe Photoshop <22.5.8, 23.4.2 - RCE
CVSS 7.8
CVE-2022-38415 HIGH
Adobe InDesign < 16.4.2 and <= 17.3 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2022-38414 HIGH
Adobe InDesign < 16.4.2 and <= 17.3 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2022-38413 HIGH
Adobe InDesign < 16.4.2 and <= 17.3 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2022-38405 HIGH
Adobe InCopy < 16.4.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2022-38404 HIGH
Adobe InCopy < 16.4.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2022-38401 HIGH
Adobe InCopy < 16.4.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2022-38411 HIGH
Adobe Animate <21.0.11, 22.0.7 - RCE
CVSS 7.8
CVE-2022-40661 HIGH
NIKON NIS-Elements Viewer 1.2100.1483.0 - Remote Code Execution via BMP Image Parsing
CVSS 7.8
CVE-2022-40660 HIGH
NIKON NIS-Elements Viewer 1.2100.1483.0 - Remote Code Execution via PSD Image Parsing
CVSS 7.8
CVE-2022-40655 HIGH
NIKON NIS-Elements Viewer 1.2100.1483.0 - Remote Code Execution via ND2 File Parsing
CVSS 7.8
CVE-2022-38701 MEDIUM
OpenHarmony <v3.1.2 - Memory Corruption
CVSS 6.2
Details
Vulnerabilities 2,334
Exploit Likelihood High