VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 120 of 160
  • CVE-2024-42648MedJul 14, 2025
    risk 0.42cvss 6.5epss 0.00

    NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

  • CVE-2025-32990MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory…

  • CVE-2025-49670MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-53184MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53183MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53182MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53181MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53180MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53179MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-45029MedJul 2, 2025
    risk 0.42cvss 6.5epss 0.00

    WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cgi.

  • CVE-2024-20522MedOct 2, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-45993MedSep 30, 2024
    risk 0.42cvss 6.5epss 0.00

    Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

  • CVE-2024-42438MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-42437MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-42436MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-38950MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

  • CVE-2024-38949MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

  • CVE-2024-29013MedJun 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.

  • CVE-2024-27243MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-34459HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.