CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2019-9502 HIGH
Synology Router Manager - Heap-based Buffer Overflow via Malicious WiFi Vendor Information Element
CVSS 7.9
CVE-2019-9501 HIGH
Synology Router Manager - Heap-based Buffer Overflow via Malicious WiFi Vendor Information Element
CVSS 7.9
CVE-2019-9500 HIGH
Broadcom brcmfmac - Buffer Overflow
CVSS 7.9
CVE-2019-15694 HIGH
TigerVNC < 1.10.1 - Heap-based Buffer Overflow in DecodeManager::decodeRect
CVSS 7.2
CVE-2019-15693 HIGH
TigerVNC < 1.10.1 - Heap-based Buffer Overflow in TightDecoder::FilterGradient
CVSS 7.2
CVE-2019-15692 HIGH
TigerVNC < 1.10.1 - Heap-based Buffer Overflow in CopyRectDecoder
CVSS 7.2
CVE-2019-16778 LOW
TensorFlow < 1.15.0 - Heap Buffer Overflow in UnsortedSegmentSum
CVSS 2.6
CVE-2019-18330 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18329 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18328 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18327 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18326 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18325 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18324 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18323 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to 5010/tcp
CVSS 9.8
CVE-2019-18297 HIGH
SPPA-T3000 MS3000 Migration Server - Local Privilege Escalation via Named Pipe Packet Crafting
CVSS 7.8
CVE-2019-18296 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to Port 5010/tcp
CVSS 9.8
CVE-2019-18295 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to Port 5010/tcp
CVSS 9.8
CVE-2019-18294 HIGH
SPPA-T3000 MS3000 Migration Server - Denial of Service via Crafted Packets to Port 5010/tcp
CVSS 7.5
CVE-2019-18293 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to Port 5010/tcp
CVSS 9.8
CVE-2019-18292 HIGH
SPPA-T3000 MS3000 Migration Server - Denial of Service via Crafted Packets to Port 5010/tcp
CVSS 7.5
CVE-2019-18291 HIGH
SPPA-T3000 MS3000 Migration Server - Denial of Service via Crafted Packets to Port 5010/tcp
CVSS 7.5
CVE-2019-18290 HIGH
SPPA-T3000 MS3000 Migration Server - Denial of Service via Crafted Packets to Port 5010/tcp
CVSS 7.5
CVE-2019-18289 CRITICAL
SPPA-T3000 MS3000 Migration Server - Denial of Service and Remote Code Execution via Crafted Packets to Port 5010/tcp
CVSS 9.8
CVE-2019-5154 HIGH
LEADTOOLS 20.0.2019.3.15 - Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 2,335
Exploit Likelihood High