CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2021-34329 HIGH
Siemens JT2Go < 13.2.0 - Heap-based Buffer Overflow in plmxmlAdapterSE70.dll via PAR File Parsing
CVSS 7.8
CVE-2021-34328 HIGH
Siemens JT2Go < 13.2.0 - Heap-based Buffer Overflow in plmxmlAdapterSE70.dll via PAR File Parsing
CVSS 7.8
CVE-2021-34327 HIGH
Siemens JT2Go < 13.2.0 - Heap-based Buffer Overflow in plmxmlAdapterSE70.dll
CVSS 7.8
CVE-2021-34326 HIGH
Siemens JT2Go < 13.2.0 - Heap-based Buffer Overflow in plmxmlAdapterSE70.dll via PAR File Parsing
CVSS 7.8
CVE-2021-34317 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.2.0 - Heap-based Buffer Overflow in BMP_loader.dll PCX Parser
CVSS 7.8
CVE-2021-34313 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.2.0 - Heap-based Buffer Overflow in TIFF Parser
CVSS 7.8
CVE-2021-34312 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.2.0 - Heap-based Buffer Overflow in TIFF Parser
CVSS 7.8
CVE-2021-33000 HIGH
WebAccess HMI Designer <2.1.9.95 - RCE
CVSS 7.8
CVE-2021-21572 HIGH
Dell Alienware M15 R6 Firmware < 1.3.3 - Authenticated Heap-based Buffer Overflow
CVSS 7.2
CVE-2021-31485 HIGH
OpenText Brava! Desktop 16.6.3.84 - Remote Code Execution via DWF File Parsing
CVSS 7.8
CVE-2021-31483 HIGH
OpenText Brava! Desktop 16.6.3.84 - Remote Code Execution via DWF File Parsing
CVSS 7.8
CVE-2021-31478 HIGH
OpenText Brava! Desktop 16.6.3.84 - Remote Code Execution via PDF Parsing
CVSS 7.8
CVE-2021-21555 MEDIUM
Dell PowerEdge Server BIOS < 2.11.2 - Heap-based Buffer Overflow in NVDIMM-N Handling
CVSS 6.1
CVE-2021-21554 MEDIUM
Dell PowerEdge and Precision BIOS < 2.9.4 - Heap-based Buffer Overflow in Intel Optane DC Persistent Memory Handling
CVSS 6.1
CVE-2021-21795 CRITICAL
Accusoft ImageGear - Heap-based Buffer Overflow in PSD read_icc_icCurve_data
CVSS 9.8
CVE-2021-28211 MEDIUM
EDK II - Heap-based Buffer Overflow in LzmaUefiDecompressGetInfo
CVSS 6.7
CVE-2021-25387 CRITICAL
libsflacextractor <SMR MAY-2021 Release 1 - RCE
CVSS 9.0
CVE-2021-25384 CRITICAL
libsdffextractor <SMR MAY-2021 Release 1 - RCE
CVSS 9.0
CVE-2021-25383 CRITICAL
libsapeextractor <SMR MAY-2021 Release 1 - RCE
CVSS 9.0
CVE-2021-26691 CRITICAL
Apache HTTP Server 2.4.0-2.4.46 - Heap-based Buffer Overflow via SessionHeader
CVSS 9.8
CVE-2021-31954 HIGH
Windows Common Log File System Driver - Elevation of Privilege
CVSS 7.8
CVE-2021-31439 HIGH
Synology DiskStation Manager 6.2-6.2.3-25426-3 - Unauthenticated Heap-based Buffer Overflow in Netatalk DSI Processing
CVSS 8.8
CVE-2021-31454 HIGH
Foxit Reader < 10.1.3.37598 and PhantomPDF < 9.7.5.29616 - Remote Code Execution via Decimal Element Handling
CVSS 7.8
CVE-2021-29464 LOW
Exiv2 < 0.27.4 - Heap-based Buffer Overflow via Crafted Image File Metadata Write
CVSS 3.3
CVE-2021-31436 HIGH
Foxit Studio Photo < 3.6.6.933 - Remote Code Execution via SGI File Handling
CVSS 7.8
Details
Vulnerabilities 2,335
Exploit Likelihood High