VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 128 of 160
  • CVE-2021-41253MedNov 8, 2021
    risk 0.38cvss 5.9epss 0.02

    Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can run into heap buffer overflows. Older…

  • CVE-2026-75883MedSep 18, 2026
    risk 0.37cvss 6.8epss 0.00

    The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a…

  • CVE-2026-75619MedAug 19, 2026
    risk 0.37cvss 5.7epss 0.00

    Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful…

  • CVE-2026-48914MedJun 12, 2026
    risk 0.37cvss 6.7epss 0.00

    A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI…

  • CVE-2026-48065MedMay 27, 2026
    risk 0.37cvss 6.7epss 0.00

    pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from libxml2 XPath evaluation of the config file, without first enforcing an upper bound. On 32-bit…

  • CVE-2026-30937MedMar 10, 2026
    risk 0.37cvss 6.8epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely…

  • CVE-2026-30931MedMar 10, 2026
    risk 0.37cvss 6.8epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is…

  • CVE-2026-28686MedMar 10, 2026
    risk 0.37cvss 6.8epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in…

  • CVE-2025-5942MedAug 14, 2025
    risk 0.37cvss —epss 0.00

    Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, an unprivileged user can trigger a heap overflow in the epdlpdrv.sys driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation can…

  • CVE-2020-14311MedJul 31, 2020
    risk 0.37cvss 5.7epss 0.00

    There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

  • CVE-2020-14310MedJul 31, 2020
    risk 0.37cvss 5.7epss 0.00

    There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage…

  • CVE-2026-81993MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2026-76918MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76917MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-66810MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-20480MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D,…

  • CVE-2026-50012MedJul 16, 2026
    risk 0.36cvss 5.5epss 0.03

    Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the…

  • CVE-2026-14355MedJul 3, 2026
    risk 0.36cvss 5.6epss 0.00

    In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the…

  • CVE-2025-55661MedJun 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

  • CVE-2025-55652MedJun 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.