CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2020-27250 HIGH
SoftMaker Office PlanMaker 2021 <Revision 1014 - Buffer Overflow
CVSS 7.8
CVE-2020-13581 HIGH
SoftMaker Office PlanMaker 2021 Revision 1014 - Heap-based Buffer Overflow in Document Parser
CVSS 7.8
CVE-2020-13572 HIGH
Accusoft ImageGear - Heap-based Buffer Overflow in GIF LZW Stream Decoder
CVSS 8.8
CVE-2020-17423 HIGH
Foxit Studio Photo 3.6.6.922 - Remote Code Execution via ARW File Handling
CVSS 7.8
CVE-2020-27249 HIGH
SoftMaker Office PlanMaker 2021 < Revision 1014 - Buffer Overflow
CVSS 7.8
CVE-2020-27248 HIGH
SoftMaker Office PlanMaker 2021 - Buffer Overflow
CVSS 7.8
CVE-2020-27247 HIGH
SoftMaker Office PlanMaker 2021 < Revision 1014 - Buffer Overflow
CVSS 7.8
CVE-2020-13586 HIGH
SoftMaker Office PlanMaker 2021 Revision 1014 - Heap-based Buffer Overflow in Excel Document SST Record
CVSS 7.8
CVE-2020-27297 CRITICAL
OPC UA Tunneller <6.3.0.8233 - Buffer Overflow
CVSS 9.8
CVE-2020-27814 HIGH
OpenJPEG < 1.5.1 - Heap-based Buffer Overflow via PNG File Handling
CVSS 7.8
CVE-2020-25687 MEDIUM
dnsmasq < 2.83 - Heap-based Buffer Overflow in DNSSEC Validation
CVSS 5.9
CVE-2020-25682 HIGH
dnsmasq < 2.83 - Heap-based Buffer Overflow in DNSSEC Name Extraction
CVSS 8.1
CVE-2020-25681 HIGH
dnsmasq < 2.83 - Heap-based Buffer Overflow in DNSSEC RRSets Validation
CVSS 8.1
CVE-2020-25683 MEDIUM
dnsmasq < 2.83 - Heap-based Buffer Overflow in DNSSEC Validation
CVSS 5.9
CVE-2020-27263 CRITICAL
KEPServerEX <6.10 - Buffer Overflow
CVSS 9.1
CVE-2020-26994 HIGH
JT2Go, Teamcenter Visualization <13.1.0 - Buffer Overflow
CVSS 8.8
CVE-2020-26987 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0 - Heap-based Buffer Overflow in TGA File Parser
CVSS 8.8
CVE-2020-26986 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0 - Heap-based Buffer Overflow in JT File Parser
CVSS 8.8
CVE-2020-26985 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0 - Heap-based Buffer Overflow in RGB and SGI File Parsing
CVSS 8.8
CVE-2020-25226 CRITICAL
SCALANCE X-200 and X-200IRT Firmware < 5.5.0 - Denial of Service via Web Server Buffer Overflow
CVSS 9.8
CVE-2020-15800 CRITICAL
SCALANCE X-200IRT/X-300 Switch Family < V5.5.0/V4.1.0 - Heap-based Buffer Overflow via Webserver Request
CVSS 9.8
CVE-2020-27841 MEDIUM
openjpeg < 2.4.0 - Heap-based Buffer Overflow in pi.c
CVSS 5.5
CVE-2020-25843 HIGH
NHIServiSignAdapter - Heap-based Buffer Overflow via Digital Credential File Path
CVSS 8.1
CVE-2020-25712 HIGH
x.org X Server < 1.20.10 - Heap-based Buffer Overflow in XkbSetDeviceInfo
CVSS 7.8
CVE-2020-25187 HIGH
Medtronic MyCareLink Smart Model 25000 Firmware - Authenticated Heap-based Buffer Overflow via Debug Command
CVSS 8.8
Details
Vulnerabilities 2,335
Exploit Likelihood High