VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 113 of 160
  • CVE-2020-25683MedJan 20, 2021
    risk 0.45cvss 5.9epss 0.86

    A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a…

  • CVE-2026-61714HigSep 18, 2026
    risk 0.44cvss 7.8epss 0.00

    FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active…

  • CVE-2026-46655HigSep 18, 2026
    risk 0.44cvss 7.8epss 0.00

    virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit…

  • CVE-2026-63422HigSep 18, 2026
    risk 0.44cvss 7.8epss 0.00

    OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow…

  • CVE-2026-90556HigSep 12, 2026
    risk 0.44cvss 7.8epss 0.00

    Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into…

  • CVE-2026-79591HigSep 10, 2026
    risk 0.44cvss 7.8epss 0.00

    A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

  • CVE-2026-21104MedSep 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2026-72985MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-72927MedSep 8, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-71350MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-71349MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-71348MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-71339MedSep 8, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-71329MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-69566MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-69449MedSep 8, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.

  • CVE-2026-69350MedSep 8, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

  • CVE-2026-68833MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-18271MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this…

  • CVE-2026-70330MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.