VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 104 of 135
  • CVE-2025-7208MedJul 9, 2025
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the…

  • CVE-2025-50054MedJun 20, 2025
    risk 0.36cvss 5.5epss 0.00

    Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash

  • CVE-2025-48910MedJun 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-31177MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

  • CVE-2024-53310MedFeb 13, 2025
    risk 0.36cvss 5.5epss 0.00

    A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long…

  • CVE-2025-0870MedJan 30, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.…

  • CVE-2024-33505MedNov 12, 2024
    risk 0.36cvss 5.6epss 0.00

    A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to…

  • CVE-2024-46488MedSep 25, 2024
    risk 0.36cvss 5.5epss 0.00

    sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2024-41437MedJul 30, 2024
    risk 0.36cvss 5.5epss 0.00

    A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.

  • CVE-2024-30066MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.01

    Winlogon Elevation of Privilege Vulnerability

  • CVE-2024-3209MedApr 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier…

  • CVE-2024-3207MedApr 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the…

  • CVE-2024-24246MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.

  • CVE-2024-1062MedFeb 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

  • CVE-2024-0911MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

  • CVE-2024-0684MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

  • CVE-2023-41276MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-41275MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the…

  • CVE-2023-41273MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-21594MedJan 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). On an SRX 5000 Series device, when executing a specific command repeatedly,…