CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2020-15196 HIGH
Tensorflow <2.3.0 - Memory Corruption
CVSS 8.5
CVE-2020-15195 HIGH
Tensorflow <2.3.1 - Buffer Overflow
CVSS 8.5
CVE-2020-6146 HIGH
Nitro Pro 13.13.2.242-13.16.2.300 - Buffer Overflow
CVSS 8.8
CVE-2020-15158 HIGH
libIEC61850 <1.4.3 - Buffer Overflow
CVSS 7.7
CVE-2020-14524 CRITICAL
Softing OPC < 4.47.0 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2020-16223 HIGH
Delta Electronics TPEditor < 1.97 - Heap-based Buffer Overflow via Crafted Project File
CVSS 7.8
CVE-2020-16207 HIGH
Advantech WebAccess HMI Designer < 2.1.9.31 - Heap-based Buffer Overflow via Crafted Project File
CVSS 7.8
CVE-2020-14311 MEDIUM
GRUB2 < 2.06 - Heap-Based Buffer Overflow via Ext Filesystem Symlink Inode Size
CVSS 5.7
CVE-2020-14310 MEDIUM
GRUB2 < 2.06 - Heap-Based Buffer Overflow via Malicious Font File
CVSS 5.7
CVE-2020-7829 HIGH
DaviewIndy <8.98.4 - Buffer Overflow
CVSS 7.8
CVE-2020-7828 HIGH
DaviewIndy <8.98.4 - Buffer Overflow
CVSS 7.8
CVE-2020-10928 HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - RCE
CVSS 8.4
CVE-2020-11061 MEDIUM
Bareos Director <= 16.2.10, 17.2.9, 18.2.8, 19.2.7 - Buffer Overflow
CVSS 6.0
CVE-2020-14482 HIGH
Delta Industrial Automation DOPSoft < 4.00.08.15 - Heap-based Buffer Overflow via Crafted Project File
CVSS 7.8
CVE-2020-4068 MEDIUM
APNSwift 1.0.0 - Heap-based Buffer Overflow in APNSwiftSigner.sign(digest:)
CVSS 6.3
CVE-2020-7586 HIGH
SIMATIC PCS 7, PDM, STEP 7, SINAMICS STARTER - Authenticated Heap-based Buffer Overflow
CVSS 7.8
CVE-2020-10638 CRITICAL
Advantech WebAccess Node <9.0.0 - RCE
CVSS 9.8
CVE-2020-8899 CRITICAL
Samsung Android OS O(8.x)-Q(10.0 - Buffer Overflow
CVSS 9.8
CVE-2020-10896 HIGH
Foxit PhantomPDF and Reader < 9.7.1.29511 - Remote Code Execution via U3D Object Handling
CVSS 7.8
CVE-2020-10646 HIGH
Fuji Electric V-Server Lite <4.0.9.0 - Buffer Overflow
CVSS 7.8
CVE-2020-6970 CRITICAL
Emerson OpenEnterprise SCADA Server 2.83 and 3.1-3.3.3 - Heap-based Buffer Overflow via Crafted Script
CVSS 9.8
CVE-2020-1711 HIGH
QEMU 2.12.0-4.2.0 - Heap-based Buffer Overflow in iSCSI Block Driver
CVSS 7.7
CVE-2020-6007 HIGH
Philips Hue Bridge 2.X <1935144020 - RCE
CVSS 7.9
CVE-2019-25327 CRITICAL
Prime95 29.8 build 6 - Remote Code Execution via User ID Input Field
CVSS 9.8
CVE-2019-15690 HIGH
LibVNCServer <0.9.12 - Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,335
Exploit Likelihood High