VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 105 of 160
  • CVE-2026-56003HigJul 8, 2026
    risk 0.48cvss 8.5epss 0.00

    A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.

  • CVE-2026-56002HigJul 8, 2026
    risk 0.48cvss 8.5epss 0.00

    A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

  • CVE-2026-56001HigJul 8, 2026
    risk 0.48cvss 8.5epss 0.00

    A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

  • CVE-2026-55999HigJul 8, 2026
    risk 0.48cvss 8.5epss 0.00

    Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

  • CVE-2026-3195HigJun 19, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix…

  • CVE-2026-44636HigMay 14, 2026
    risk 0.48cvss 7.4epss 0.00

    libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and…

  • CVE-2026-35433HigMay 12, 2026
    risk 0.48cvss 7.3epss 0.01

    Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-4892HigMay 11, 2026
    risk 0.48cvss 8.4epss 0.01

    A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

  • CVE-2026-40706HigApr 21, 2026
    risk 0.48cvss 8.4epss 0.00

    In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat,…

  • CVE-2026-32710HigMar 20, 2026
    risk 0.48cvss 8.5epss 0.01

    MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code…

  • CVE-2024-7730HigNov 14, 2024
    risk 0.48cvss 7.4epss 0.00

    A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of…

  • CVE-2024-36702HigJun 11, 2024
    risk 0.48cvss 7.4epss 0.00

    libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

  • CVE-2024-32624HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.

  • CVE-2024-32620HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32619HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32618HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

  • CVE-2024-32616HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

  • CVE-2024-32613HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

  • CVE-2024-32612HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.

  • CVE-2024-29165HigMay 14, 2024
    risk 0.48cvss 7.4epss 0.00

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.