CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2019-6740 HIGH
Samsung Galaxy S9 Firmware < 2019-01 - Remote Code Execution via ASN.1 Parser Heap Overflow
CVSS 8.8
CVE-2019-3846 HIGH
Linux Kernel 3.0-3.16.69 - Heap-based Buffer Overflow in mwifiex Wireless Module
CVSS 8.8
CVE-2019-5436 HIGH
libcurl 7.19.4-7.64.1 - Heap-based Buffer Overflow in TFTP Receiving Code
CVSS 7.8
CVE-2019-3568 CRITICAL KEV
WhatsApp < 2.19.134 and WhatsApp Business < 2.19.51 - Remote Code Execution via RTCP Packets
CVSS 9.8
CVE-2019-9136 HIGH
DaviewIndy <= 8.98.7 - Heap-based Buffer Overflow via Malformed JPEG2000 File
CVSS 7.8
CVE-2019-9135 HIGH
datools daviewindy < 8.98.7 - Heap-based Buffer Overflow via Malformed DIB File
CVSS 7.8
CVE-2019-10951 HIGH
Delta Industrial Automation CNCSoft ScreenEditor <= 1.00.88 - Heap-based Buffer Overflow via Project File Processing
CVSS 7.8
CVE-2019-8274 CRITICAL
UltraVNC < 1.2.2.3 - Heap-based Buffer Overflow in File Transfer Offer Handler
CVSS 9.8
CVE-2019-8273 CRITICAL
UltraVNC < 1.2.2.3 - Heap-based Buffer Overflow in File Transfer Request Handler
CVSS 9.8
CVE-2019-8271 CRITICAL
UltraVNC < 1.2.2.3 - Heap-based Buffer Overflow in File Transfer Handler
CVSS 9.8
CVE-2019-5019 CRITICAL
Rainbow PDF Office Server Document Converter V7.0 Pro R1 - Buffer O...
CVSS 9.8
CVE-2019-8262 CRITICAL
UltraVNC < 1.2.2.3 - Heap-based Buffer Overflow in Ultra Decoder
CVSS 9.8
CVE-2019-8258 CRITICAL
UltraVNC < 1.2.2.3 - Heap-based Buffer Overflow
CVSS 9.8
CVE-2019-6539 HIGH
WECON LeviStudioU <= 1.8.56 - Heap-based Buffer Overflow
CVSS 7.8
CVE-2018-8800 CRITICAL
rdesktop <= 1.8.3 - Heap-Based Buffer Overflow in ui_clip_handle_data
CVSS 9.8
CVE-2018-8797 CRITICAL
rdesktop <= 1.8.3 - Heap-Based Buffer Overflow in process_plane()
CVSS 9.8
CVE-2018-8793 CRITICAL
rdesktop <= 1.8.3 - Heap-Based Buffer Overflow in cssp_read_tsrequest
CVSS 9.8
CVE-2018-18981 HIGH
Rockwell Automation FactoryTalk Services Platform < 2.90 - Unauthenticated Denial of Service via Crafted Packet Flood
CVSS 7.5
CVE-2018-6345 CRITICAL
HHVM < 3.27.5 - Heap-based Buffer Overflow in number_format Function
CVSS 9.8
CVE-2018-6344 HIGH
WhatsApp < 2.18.293 - Denial of Service via Malformed RTP Packet
CVSS 7.5
CVE-2018-11457 HIGH
SINUMERIK 828D/840D sl < V4.7 SP6 HF1/V4.8 SP3 - RCE via Port 4842/tcp
CVSS 8.1
CVE-2018-19093 HIGH
libIEC61850 v1.3 - Heap-based Buffer Overflow in ControlObjectClient_setCommandTerminationHandler
CVSS 7.5
CVE-2018-14653 HIGH
Gluster <4.1.4, 3.12 - Buffer Overflow
CVSS 8.8
CVE-2018-16839 MEDIUM
curl 7.33.0-7.61.1 - Denial of Service via SASL Authentication Buffer Overrun
CVSS 4.3
CVE-2018-14794 CRITICAL
Fuji Electric Alpha5 Smart Loader <3.7 - Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 2,335
Exploit Likelihood High