CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 117 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62381 | Med | 0.43 | 6.6 | 0.00 | Aug 22, 2026 | luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255… | ||
| CVE-2026-63633 | Hig | 0.43 | — | 0.00 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A… | ||
| CVE-2026-25749 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When… | ||
| CVE-2025-51089 | Med | 0.43 | 6.5 | 0.06 | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow. | ||
| CVE-2025-5915 | Med | 0.43 | 6.6 | 0.00 | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated… | ||
| CVE-2025-31164 | Med | 0.43 | 6.6 | 0.00 | Mar 28, 2025 | heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. | ||
| CVE-2025-21256 | Med | 0.43 | 6.6 | 0.01 | Jan 14, 2025 | Windows Digital Media Elevation of Privilege Vulnerability | ||
| CVE-2024-49094 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-49081 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | ||
| CVE-2024-43480 | Med | 0.43 | 6.6 | 0.01 | Oct 8, 2024 | Azure Service Fabric for Linux Remote Code Execution Vulnerability | ||
| CVE-2023-3463 | Med | 0.43 | 6.6 | 0.00 | Jul 19, 2023 | All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free,… | ||
| CVE-2023-1170 | Med | 0.43 | 6.6 | 0.01 | Mar 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | ||
| CVE-2022-3437 | Med | 0.43 | 6.5 | 0.04 | Jan 12, 2023 | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory… | ||
| CVE-2023-21560 | Med | 0.43 | 6.6 | 0.01 | Jan 10, 2023 | Windows Boot Manager Security Feature Bypass Vulnerability | ||
| CVE-2018-14618 | Hig | 0.43 | 7.5 | 0.11 | Sep 5, 2018 | curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length… | ||
| CVE-2018-10840 | Med | 0.43 | 6.6 | 0.01 | Jul 16, 2018 | Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image. | ||
| CVE-2026-67549 | Hig | 0.42 | 7.6 | 0.00 | Sep 18, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer.… | ||
| CVE-2026-81634 | Hig | 0.42 | 7.5 | 0.00 | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor… | ||
| CVE-2026-90439 | Med | 0.42 | 6.5 | 0.00 | Sep 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a… | ||
| CVE-2026-86870 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2026 | A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination. |
- risk 0.43cvss 6.6epss 0.00
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255…
- risk 0.43cvss —epss 0.00
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A…
- risk 0.43cvss 6.6epss 0.00
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When…
- risk 0.43cvss 6.5epss 0.06
Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.
- risk 0.43cvss 6.6epss 0.00
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated…
- risk 0.43cvss 6.6epss 0.00
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.
- risk 0.43cvss 6.6epss 0.01
Windows Digital Media Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Azure Service Fabric for Linux Remote Code Execution Vulnerability
- risk 0.43cvss 6.6epss 0.00
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free,…
- risk 0.43cvss 6.6epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
- risk 0.43cvss 6.5epss 0.04
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory…
- risk 0.43cvss 6.6epss 0.01
Windows Boot Manager Security Feature Bypass Vulnerability
- risk 0.43cvss 7.5epss 0.11
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length…
- risk 0.43cvss 6.6epss 0.01
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
- risk 0.42cvss 7.6epss 0.00
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer.…
- risk 0.42cvss 7.5epss 0.00
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor…
- risk 0.42cvss 6.5epss 0.00
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a…
- risk 0.42cvss 6.5epss 0.00
A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.