VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 103 of 160
  • CVE-2023-32157HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.00

    Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious…

  • CVE-2023-32140HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit…

  • CVE-2024-25048HigApr 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.

  • CVE-2024-28896HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2023-45591HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in the context of the binary. This may result in a Denial-of-Service (DoS) condition,…

  • CVE-2024-0040HigFeb 16, 2024
    risk 0.49cvss 7.5epss 0.02

    In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-21348HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.02

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

  • CVE-2024-21347HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-3430HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash,…

  • CVE-2023-4692HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap…

  • CVE-2022-24834HigJul 13, 2023
    risk 0.49cvss 7.0epss 0.41

    Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua…

  • CVE-2023-24474HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

  • CVE-2023-32324HigJun 1, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote…

  • CVE-2023-32307HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in…

  • CVE-2023-28227HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.07

    Windows Bluetooth Driver Remote Code Execution Vulnerability

  • CVE-2023-21695HigFeb 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-44654HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been…

  • CVE-2021-45918HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate…

  • CVE-2022-22188HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine (PFE) of Juniper Networks Junos OS allows a network-based unauthenticated attacker to flood the device with traffic leading to a Denial of Service (DoS). The…

  • CVE-2021-34583HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.08

    Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.