CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,334 vulnerabilities with CWE-122
CVE-2021-26603 HIGH
Bandisoft ARK Library < 7.13.0.3 - Heap-based Buffer Overflow in Ark_DigPathA
CVSS 8.6
CVE-2021-3770 HIGH
vim < 8.2.3408 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-28560 HIGH
Adobe Acrobat and Reader DC < 21.001.20150 & < 17.011.30194 - Heap-based Buffer Overflow
CVSS 8.8
CVE-2021-28558 HIGH
Adobe Acrobat/Reader DC < 21.001.20150 & < 17.011.30194 - Heap-based Buffer Overflow
CVSS 8.8
CVE-2021-36073 HIGH
Adobe Bridge <11.1 - Buffer Overflow
CVSS 7.8
CVE-2021-36065 HIGH
Adobe Photoshop <22.4.3 - Buffer Overflow
CVSS 7.8
CVE-2021-36056 MEDIUM
XMP Toolkit SDK < 2020.1 - Heap-based Buffer Overflow via Crafted File
CVSS 5.5
CVE-2021-36054 LOW
XMP Toolkit SDK <2020.1 - Buffer Overflow
CVSS 3.3
CVE-2021-36050 HIGH
XMP Toolkit SDK < 2020.1 - Heap-based Buffer Overflow via Crafted File
CVSS 7.8
CVE-2021-33007 HIGH
Delta Electronics TPEditor <1.98.06 - Buffer Overflow
CVSS 7.8
CVE-2021-28629 HIGH
Adobe Animate < 21.0.6 - Unauthenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-28620 HIGH
Adobe Animate < 21.0.6 - Unauthenticated Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2021-28610 HIGH
Adobe After Effects < 18.2 - Heap-based Buffer Overflow via Crafted File
CVSS 7.8
CVE-2021-28608 HIGH
Adobe After Effects < 18.2 - Heap-based Buffer Overflow via Crafted File
CVSS 7.8
CVE-2021-28604 HIGH
Adobe After Effects < 18.2 - Heap-based Buffer Overflow via Crafted File
CVSS 7.8
CVE-2021-28603 HIGH
Adobe After Effects < 18.2 - Heap-based Buffer Overflow via Crafted File
CVSS 7.8
CVE-2021-28638 HIGH
Acrobat Reader DC < 21.005.20054 and < 17.011.30197 - Unauthenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2021-28624 HIGH
Adobe Bridge < 11.0.2 - Heap-based Buffer Overflow via Malicious File
CVSS 7.8
CVE-2021-21825 CRITICAL
AT&T Labs Xmill 0.7 - Heap-based Buffer Overflow in XML Decompression PlainTextUncompressor
CVSS 9.8
CVE-2021-21810 CRITICAL
AT&T Labs Xmill 0.7 - Heap-based Buffer Overflow in XML ParseAttribs
CVSS 9.8
CVE-2021-21830 CRITICAL
AT&T Labs Xmill 0.7 - Heap-based Buffer Overflow in XML Decompression LabelDict::Load
CVSS 9.8
CVE-2021-21829 CRITICAL
AT&T Labs Xmill 0.7 - Heap-based Buffer Overflow in XML Decompression EnumerationUncompressor::UncompressItem
CVSS 9.8
CVE-2021-33485 CRITICAL
CODESYS Control Runtime <3.5.17.10 - Buffer Overflow
CVSS 9.8
CVE-2021-24036 CRITICAL
Facebook Folly < 2021.07.22.00 and HHVM < 4.80.5 - Heap-Based Buffer Overflow via IOBuf Size Mismanagement
CVSS 9.8
CVE-2021-34329 HIGH
Siemens JT2Go < 13.2.0 - Heap-based Buffer Overflow in plmxmlAdapterSE70.dll via PAR File Parsing
CVSS 7.8
Details
Vulnerabilities 2,334
Exploit Likelihood High