CWE-122

High likelihood

Heap-based Buffer Overflow

Parent: CWE-788 - Access of Memory Location After End of Buffer

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

2,335 vulnerabilities with CWE-122
CVE-2018-7519 MEDIUM
Omron CX-Supervisor < 3.30 - Heap-based Buffer Overflow via Malformed Project File
CVSS 5.3
CVE-2018-1165 HIGH
Joyent SmartOS release-20170803-20170803T064301Z - Authenticated Heap-based Buffer Overflow in SMB_IOC_SVCENUM IOCTL
CVSS 7.0
CVE-2017-7908 HIGH
Gigasoft ProEssentials < 5 - Heap-Based Buffer Overflow via ActiveX Control
CVSS 7.6
CVE-2017-2591 LOW
389 Directory Server < 1.3.6 - Out-of-bounds Read in Attribute Uniqueness Plugin
CVSS 3.7
CVE-2017-9636 CRITICAL
Mitsubishi E-Designer <7.52 Build 344 - Memory Corruption
CVSS 9.8
CVE-2017-16737 HIGH
WECON Technology LEVI Studio HMI Editor <1.8.29 - Buffer Overflow
CVSS 7.8
CVE-2017-16717 HIGH
WECON LeviStudio HMI - Buffer Overflow
CVSS 8.6
CVE-2017-13090 HIGH
GNU Wget < 1.19.2 - Heap-Based Buffer Overflow via Negative Chunk Length
CVSS 8.8
CVE-2017-12704 HIGH
Advantech WebAccess < 8.2 - Heap-Based Buffer Overflow
CVSS 8.8
CVE-2017-7555 CRITICAL
augeas <= 1.8.0 - Heap-Based Buffer Overflow via Escaped String Handling
CVSS 9.8
CVE-2017-9050 HIGH
libxml2 20904-GITv2.9.4-16-g0741801 - Buffer Overflow
CVSS 7.5
CVE-2017-6037 HIGH
Wecon Technologies LEVI Studio HMI Editor < 1.8.1 - Heap-Based Buffer Overflow via Malicious Project File
CVSS 8.8
CVE-2017-5225 HIGH
libtiff 4.0.7 - Heap Buffer Overflow via Crafted BitsPerSample Value
CVSS 8.8
CVE-2016-2123 HIGH
Samba 4.0.0-4.5.2 - Authenticated Memory Corruption via LDAP dnsRecord Attribute
CVSS 8.8
CVE-2016-9580 LOW
OpenJPEG 2.1.2 - Integer Overflow to Heap Buffer Overflow in tiftoimage
CVSS 3.3
CVE-2016-8654 HIGH
jasper < 2.0.0 - Heap-Based Buffer Overflow in QMFB JPC Codec
CVSS 7.8
CVE-2016-9581 LOW
OpenJPEG 2.1.2 - Heap Buffer Overflow in convert_32s_C1P1
CVSS 3.3
CVE-2016-8622 LOW
libcurl < 7.51.0 - Integer Overflow in URL Percent-Encoding Decode Function
CVSS 3.7
CVE-2016-9603 MEDIUM
QEMU < 2.9.0 - Heap Buffer Overflow in Cirrus CLGD 54xx VGA Emulator
CVSS 5.5
CVE-2016-9577 HIGH
spice < 0.13.90 - Authenticated Heap Overflow via Crafted Protocol Messages
CVSS 7.5
CVE-2016-9586 MEDIUM
curl < 7.52.0 - Buffer Overflow via Large Floating Point Output in printf Implementation
CVSS 5.9
CVE-2016-1834 HIGH
libxml2 <2.9.4 - Buffer Overflow
CVSS 7.8
CVE-2016-1762 HIGH
libxml2 <2.9.4 - DoS
CVSS 8.1
CVE-2015-6457 HIGH
Moxa SoftCMS < 1.3 - Buffer Overflow
CVSS 8.8
CVE-2015-3113 CRITICAL KEV
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVSS 9.8
Details
Vulnerabilities 2,335
Exploit Likelihood High