CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 112 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22660 | Hig | 0.46 | 7.0 | 0.01 | Apr 5, 2023 | A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To… | ||
| CVE-2022-34400 | Hig | 0.46 | 7.1 | 0.00 | Feb 1, 2023 | Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM. | ||
| CVE-2023-21733 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-31144 | Hig | 0.46 | 7.0 | 0.03 | Jul 19, 2022 | Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is… | ||
| CVE-2020-13600 | Hig | 0.46 | 7.0 | 0.00 | May 25, 2021 | Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr | ||
| CVE-2020-27752 | Hig | 0.46 | 7.1 | 0.01 | Dec 8, 2020 | A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an… | ||
| CVE-2018-1165 | Hig | 0.46 | 7.0 | 0.01 | Feb 21, 2018 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | ||
| CVE-2016-1762 | Hig | 0.46 | 8.1 | 0.07 | Mar 24, 2016 | The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | ||
| CVE-2026-61721 | Hig | 0.45 | 8.0 | 0.00 | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A… | ||
| CVE-2026-70578 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69564 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69563 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69492 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69468 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69394 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-81851 | Med | 0.45 | — | 0.00 | Aug 28, 2026 | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | ||
| CVE-2026-21399 | Med | 0.45 | — | 0.00 | Aug 11, 2026 | Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low… | ||
| CVE-2026-24922 | Med | 0.45 | 6.9 | 0.00 | Feb 6, 2026 | Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-65079 | Med | 0.45 | — | 0.01 | Feb 3, 2026 | A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user. | ||
| CVE-2020-25687 | Med | 0.45 | 5.9 | 0.87 | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a… |
- risk 0.46cvss 7.0epss 0.01
A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To…
- risk 0.46cvss 7.1epss 0.00
Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.
- risk 0.46cvss 7.0epss 0.00
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.03
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is…
- risk 0.46cvss 7.0epss 0.00
Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr
- risk 0.46cvss 7.1epss 0.01
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an…
- risk 0.46cvss 7.0epss 0.01
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
- risk 0.46cvss 8.1epss 0.07
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
- risk 0.45cvss 8.0epss 0.00
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A…
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss —epss 0.00
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
- risk 0.45cvss —epss 0.00
Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low…
- risk 0.45cvss 6.9epss 0.00
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.45cvss —epss 0.01
A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
- risk 0.45cvss 5.9epss 0.87
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a…