VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 114 of 160
  • CVE-2026-70304MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65799MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65797MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62886HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-62883MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62881MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62871HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-62769MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62699MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-70638HigAug 6, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer…

  • CVE-2026-35591HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer…

  • CVE-2026-47747HigJun 16, 2026
    risk 0.44cvss 7.8epss 0.00

    stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in…

  • CVE-2026-47749HigJun 16, 2026
    risk 0.44cvss 7.8epss 0.00

    stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files.…

  • CVE-2026-47311HigMay 19, 2026
    risk 0.44cvss 7.8epss 0.00

    Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

  • CVE-2026-42046HigMay 11, 2026
    risk 0.44cvss 7.8epss 0.00

    libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format.…

  • CVE-2026-5405HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

  • CVE-2026-5403HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

  • CVE-2026-32223MedApr 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-33298HigMar 24, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a…

  • CVE-2026-3082HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.01

    GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…