VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 115 of 160
  • CVE-2026-2920HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.01

    GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-27940HigMar 12, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past…

  • CVE-2026-24288MedMar 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-20876MedJan 13, 2026
    risk 0.44cvss 6.7epss 0.01

    Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20774MedDec 2, 2025
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID:…

  • CVE-2025-63701MedNov 14, 2025
    risk 0.44cvss 6.8epss 0.00

    A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size…

  • CVE-2025-20741MedNov 4, 2025
    risk 0.44cvss 6.7epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422;…

  • CVE-2025-5517MedOct 20, 2025
    risk 0.44cvss 6.8epss 0.00

    Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB Terra AC wallbox (MID/ CE) -Terra AC Juno CE, ABB Terra AC wallbox (MID/ CE) -Terra AC PTB, ABB Terra AC wallbox (JP).This…

  • CVE-2025-36902MedSep 4, 2025
    risk 0.44cvss 6.7epss 0.00

    In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-54630MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-48071HigJul 31, 2025
    risk 0.44cvss 7.8epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep…

  • CVE-2025-4657MedJul 17, 2025
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2024-0145MedFeb 12, 2025
    risk 0.44cvss 6.8epss 0.01

    NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to code execution and data tampering.

  • CVE-2024-9632HigOct 30, 2024
    risk 0.44cvss 7.8epss 0.01

    A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions…

  • CVE-2024-43526MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43525MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43523MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-20517MedOct 2, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-20516MedOct 2, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-6258MedSep 13, 2024
    risk 0.44cvss 6.8epss 0.00

    BT: Missing length checks of net_buf in rfcomm_handle_data