CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2021-38439 HIGH
GurumDDS - Heap-based Buffer Overflow
CVSS 8.6
CVE-2021-40426 HIGH
Sound Exchange libsox 14.4.2 - Heap-based Buffer Overflow in sphere.c start_read()
CVSS 8.8
CVE-2021-21948 HIGH
AnyCubic Chitubox AnyCubic Plugin 1.0.0 - Heap-Based Buffer Overflow via Crafted GF File
CVSS 7.8
CVE-2021-21947 HIGH
Accusoft ImageGear 19.10 - Heap-Based Buffer Overflow in JPEG-JFIF Lossless Huffman Parser
CVSS 8.8
CVE-2021-21946 HIGH
Accusoft ImageGear 19.10 - Heap-based Buffer Overflow in JPEG-JFIF Lossless Huffman Parser
CVSS 8.8
CVE-2021-21945 HIGH
Accusoft ImageGear 19.10 - Heap-based Buffer Overflow in TIFF Parser
CVSS 8.8
CVE-2021-21944 HIGH
Accusoft ImageGear 19.10 - Heap-based Buffer Overflow in TIFF Parser
CVSS 8.8
CVE-2021-21943 HIGH
Accusoft ImageGear 19.10 - Heap-Based Buffer Overflow in XWD Parser
CVSS 8.8
CVE-2021-21942 HIGH
Accusoft ImageGear - Heap-based Buffer Overflow in TIFF YCbCr Image Parser
CVSS 8.8
CVE-2021-21914 HIGH
Accusoft ImageGear - Heap-Based Buffer Overflow via DecoderStream::Append
CVSS 8.8
CVE-2021-23165 CRITICAL
htmldoc < 1.9.12 - Heap-based Buffer Overflow in pspdf_prepare_outpages
CVSS 9.8
CVE-2021-43305 HIGH
Clickhouse < 21.10.2.15 - Heap-based Buffer Overflow in LZ4 Decompression
CVSS 8.8
CVE-2021-43304 HIGH
Clickhouse < 21.10.2.15 - Heap-based Buffer Overflow in LZ4 Compression Codec
CVSS 8.8
CVE-2021-42018 MEDIUM
Siemens RUGGEDCOM ROS - Heap-based Buffer Overflow in Memory Allocation
CVSS 5.9
CVE-2021-46653 HIGH
Bentley MicroStation and View < 10.16.02 - Remote Code Execution via BMP Image Parsing
CVSS 7.8
CVE-2021-46648 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-46647 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-46606 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-46605 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-46603 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-46577 HIGH
Bentley MicroStation CONNECT 10.16.0.80 - RCE
CVSS 7.8
CVE-2021-21958 HIGH
Hancom Office 2020 11.0.0.2353 - Heap-based Buffer Overflow via Malformed File
CVSS 7.8
CVE-2021-44000 HIGH
Siemens JT2Go < 13.2.0.7 - Heap-based Buffer Overflow via PAR File Parsing
CVSS 7.8
CVE-2021-3861 HIGH
Zephyr >= v2.6.0 - Heap-based Buffer Overflow
CVSS 8.2
CVE-2021-3835 HIGH
Zephyr >= v2.6.0 - Heap-based Buffer Overflow
CVSS 8.2
Details
Vulnerabilities 2,334
Exploit Likelihood High