CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 113 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25683 | Med | 0.45 | 5.9 | 0.86 | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a… | ||
| CVE-2026-61714 | Hig | 0.44 | 7.8 | 0.00 | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active… | ||
| CVE-2026-46655 | Hig | 0.44 | 7.8 | 0.00 | Sep 18, 2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit… | ||
| CVE-2026-63422 | Hig | 0.44 | 7.8 | 0.00 | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow… | ||
| CVE-2026-90556 | Hig | 0.44 | 7.8 | 0.00 | Sep 12, 2026 | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into… | ||
| CVE-2026-79591 | Hig | 0.44 | 7.8 | 0.00 | Sep 10, 2026 | A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index. | ||
| CVE-2026-21104 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2026 | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code. | ||
| CVE-2026-72985 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-72927 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-71350 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-71349 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-71348 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-71339 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-71329 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-69566 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-69449 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. | ||
| CVE-2026-69350 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68833 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-18271 | Med | 0.44 | 6.8 | 0.00 | Aug 20, 2026 | Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this… | ||
| CVE-2026-70330 | Med | 0.44 | 6.7 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
- risk 0.45cvss 5.9epss 0.86
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a…
- risk 0.44cvss 7.8epss 0.00
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active…
- risk 0.44cvss 7.8epss 0.00
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit…
- risk 0.44cvss 7.8epss 0.00
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow…
- risk 0.44cvss 7.8epss 0.00
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into…
- risk 0.44cvss 7.8epss 0.00
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this…
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.