CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2021-41253 MEDIUM
Zydis < 3.2.0 - Heap Buffer Overflow via Uninitialized String Object in Formatter Buffer
CVSS 5.9
CVE-2021-3927 HIGH
vim < 8.2.3581 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-22564 MEDIUM
libjxl < 0.6.0 - Heap-based Buffer Overflow via Out-of-Order Group Processing
CVSS 4.5
CVE-2021-3756 CRITICAL
libmysofa < 1.2.1 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2021-3903 HIGH
vim < 8.2.3564 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-34583 HIGH
WAGO 750 Series Firmware - Heap-based Buffer Overflow via Crafted Web Server Requests
CVSS 7.5
CVE-2021-3872 HIGH
vim < 8.2.3487 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-33023 CRITICAL
Advantech WebAccess <9.02 - Buffer Overflow
CVSS 9.8
CVE-2021-3875 MEDIUM
vim < 8.2.3489 - Heap-based Buffer Overflow
CVSS 5.5
CVE-2021-21940 CRITICAL
Anker Eufy Homebase 2 2.1.6.9h - Heap-based Buffer Overflow in pushMuxer processRtspInfo
CVSS 10.0
CVE-2021-37199 HIGH
SINUMERIK 808D and 828D < 4.95 - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 7.5
CVE-2021-25495 HIGH
Samsung Notes <4.3.02.61 - Buffer Overflow
CVSS 7.3
CVE-2021-25479 HIGH
Exynos CP Chipset <SMR Oct-2021 Release 1 - Buffer Overflow
CVSS 7.2
CVE-2021-25475 LOW
DSP kernel driver <SMR Oct-2021 Release 1 - Buffer Overflow
CVSS 3.9
CVE-2021-31986 MEDIUM
AXIS OS Heap-based Buffer Overflow via SMTP Notification Parameters
CVSS 6.8
CVE-2021-3625 CRITICAL
Zephyr 2.5.0-2.6.9 - Heap-based Buffer Overflow in USB DFU DNLOAD
CVSS 9.6
CVE-2021-32626 HIGH
Redis 2.6-5.0.13 - Heap-based Buffer Overflow via Lua Script Execution
CVSS 7.5
CVE-2021-36051 HIGH
XMP Toolkit SDK < 2020.1 - Buffer Overflow via Crafted .cpp File
CVSS 7.8
CVE-2021-39863 HIGH
Adobe Acrobat and Reader DC < 21.005.20060 - Heap-based Buffer Overflow via Crafted PDF File
CVSS 7.8
CVE-2021-39823 HIGH
Adobe SVG Native Viewer <= 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d - Heap-based Buffer Overflow via Malicious SVG File
CVSS 7.8
CVE-2021-32959 HIGH
Aveva SuiteLink Server <= 3.2.002 - Heap-based Buffer Overflow
CVSS 8.1
CVE-2021-34770 CRITICAL
Cisco IOS XE - Unauthenticated Remote Code Execution or Denial of Service via CAPWAP Packet Validation
CVSS 10.0
CVE-2021-38404 HIGH
Delta Electronic DOPSoft 2 <2.00.07 - Buffer Overflow
CVSS 7.8
CVE-2021-3778 HIGH
vim < 8.2.3409 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-25449 MEDIUM
libsapeextractor <SMR Sep-2021 Release 1 - RCE
CVSS 6.5
Details
Vulnerabilities 2,334
Exploit Likelihood High