CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 108 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49089 | Hig | 0.47 | 7.2 | 0.02 | Dec 12, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-37041 | Hig | 0.47 | 7.2 | 0.01 | Nov 22, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the… | ||
| CVE-2024-38025 | Hig | 0.47 | 7.2 | 0.02 | Jul 9, 2024 | Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | ||
| CVE-2024-21778 | Hig | 0.47 | 7.2 | 0.01 | Jul 8, 2024 | A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this… | ||
| CVE-2024-26202 | Hig | 0.47 | 7.2 | 0.02 | Apr 9, 2024 | DHCP Server Service Remote Code Execution Vulnerability | ||
| CVE-2024-26195 | Hig | 0.47 | 7.2 | 0.02 | Apr 9, 2024 | DHCP Server Service Remote Code Execution Vulnerability | ||
| CVE-2024-2212 | Hig | 0.47 | 7.3 | 0.01 | Mar 26, 2024 | In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap… | ||
| CVE-2024-22453 | Hig | 0.47 | 7.2 | 0.00 | Mar 19, 2024 | Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory. | ||
| CVE-2023-6779 | Hig | 0.47 | 8.2 | 0.03 | Jan 31, 2024 | An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an… | ||
| CVE-2023-35350 | Hig | 0.47 | 7.2 | 0.01 | Jul 11, 2023 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | ||
| CVE-2023-30763 | Hig | 0.47 | 7.2 | 0.00 | May 12, 2023 | Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-28254 | Hig | 0.47 | 7.2 | 0.01 | Apr 11, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2023-23400 | Hig | 0.47 | 7.2 | 0.01 | Mar 14, 2023 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-25495 | Hig | 0.47 | 7.3 | 0.00 | Oct 6, 2021 | A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution. | ||
| CVE-2021-25479 | Hig | 0.47 | 7.2 | 0.01 | Oct 6, 2021 | A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution. | ||
| CVE-2021-21572 | Hig | 0.47 | 7.2 | 0.00 | Jun 24, 2021 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | ||
| CVE-2026-55556 | Hig | 0.46 | — | 0.01 | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic Authorization value exceeds its fixed… | ||
| CVE-2026-53938 | Hig | 0.46 | 8.2 | 0.00 | Sep 9, 2026 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the… | ||
| CVE-2026-81389 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-70573 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
- risk 0.47cvss 7.2epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…
- risk 0.47cvss 7.2epss 0.02
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this…
- risk 0.47cvss 7.2epss 0.02
DHCP Server Service Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
DHCP Server Service Remote Code Execution Vulnerability
- risk 0.47cvss 7.3epss 0.01
In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap…
- risk 0.47cvss 7.2epss 0.00
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
- risk 0.47cvss 8.2epss 0.03
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an…
- risk 0.47cvss 7.2epss 0.01
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.00
Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.47cvss 7.2epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.3epss 0.00
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
- risk 0.47cvss 7.2epss 0.01
A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
- risk 0.47cvss 7.2epss 0.00
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
- risk 0.46cvss —epss 0.01
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic Authorization value exceeds its fixed…
- risk 0.46cvss 8.2epss 0.00
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the…
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.