CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 102 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-32396 | Hig | 0.49 | 7.5 | 0.00 | May 7, 2025 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet. | ||
| CVE-2025-30644 | Hig | 0.49 | 7.5 | 0.00 | Apr 9, 2025 | A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an… | ||
| CVE-2025-26668 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29070 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2025 | A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color… | ||
| CVE-2025-26634 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2025 | Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-27091 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2025 | OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulnerability is due to a race condition… | ||
| CVE-2025-21172 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2025-21171 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | .NET Remote Code Execution Vulnerability | ||
| CVE-2024-8798 | Hig | 0.49 | 7.5 | 0.00 | Dec 16, 2024 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. | ||
| CVE-2024-40763 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2024 | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution. | ||
| CVE-2024-43579 | Hig | 0.49 | 7.6 | 0.01 | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2024-43578 | Hig | 0.49 | 7.6 | 0.01 | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2024-6259 | Hig | 0.49 | 7.6 | 0.01 | Sep 13, 2024 | BT: HCI: adv_ext_report Improper discarding in adv_ext_report | ||
| CVE-2024-6135 | Hig | 0.49 | 7.6 | 0.00 | Sep 13, 2024 | BT:Classic: Multiple missing buf length checks | ||
| CVE-2024-40764 | Hig | 0.49 | 7.5 | 0.01 | Jul 18, 2024 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). | ||
| CVE-2024-39518 | Hig | 0.49 | 7.5 | 0.00 | Jul 10, 2024 | A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS). When the device is… | ||
| CVE-2024-36843 | Hig | 0.49 | 7.5 | 0.01 | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | ||
| CVE-2024-35434 | Hig | 0.49 | 7.5 | 0.01 | May 29, 2024 | Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet. | ||
| CVE-2023-6349 | Hig | 0.49 | 7.5 | 0.00 | May 27, 2024 | A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above | ||
| CVE-2024-5228 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2024 | TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not… |
- risk 0.49cvss 7.5epss 0.00
An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.
- risk 0.49cvss 7.5epss 0.00
A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Series allows an attacker to send a specific DHCP packet to the device, leading to an…
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color…
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
OpenH264 is a free license codec library which supports H.264 encoding and decoding. A vulnerability in the decoding functions of OpenH264 codec library could allow a remote, unauthenticated attacker to trigger a heap overflow. This vulnerability is due to a race condition…
- risk 0.49cvss 7.5epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
.NET Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.00
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
- risk 0.49cvss 7.6epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.49cvss 7.6epss 0.01
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
- risk 0.49cvss 7.6epss 0.00
BT:Classic: Multiple missing buf length checks
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
- risk 0.49cvss 7.5epss 0.00
A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a steady increase in memory utilization, ultimately leading to a Denial of Service (DoS). When the device is…
- risk 0.49cvss 7.5epss 0.01
libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
- risk 0.49cvss 7.5epss 0.01
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet.
- risk 0.49cvss 7.5epss 0.00
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above
- risk 0.49cvss 7.5epss 0.01
TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not…