VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 129 of 135
  • CVE-2025-29912CriMar 17, 2025
    risk 0.00cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer…

  • CVE-2025-1788MedMar 1, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_encode in the library /librz/util/utf8.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has…

  • CVE-2024-55627MedJan 6, 2025
    risk 0.00cvss 5.9epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an…

  • CVE-2024-45306MedSep 2, 2024
    risk 0.00cvss 4.5epss 0.00

    Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we…

  • CVE-2024-43790MedAug 22, 2024
    risk 0.00cvss 4.5epss 0.00

    Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf). When right-left mode (:set rl) is enabled, the search…

  • CVE-2024-32671CriJul 29, 2024
    risk 0.00cvss 9.8epss 0.00

    Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

  • CVE-2024-32664MedMay 7, 2024
    risk 0.00cvss 5.3epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19.…

  • CVE-2024-34408MedMay 3, 2024
    risk 0.00cvss 5.3epss 0.00

    Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.

  • CVE-2023-50230HigMay 3, 2024
    risk 0.00cvss 8.0epss 0.01

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-50229HigMay 3, 2024
    risk 0.00cvss 8.0epss 0.02

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-50009HigApr 19, 2024
    risk 0.00cvss 8.0epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

  • CVE-2024-31582HigApr 17, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.

  • CVE-2024-24335HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

  • CVE-2024-24334HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

  • CVE-2024-28231CriMar 20, 2024
    risk 0.00cvss 9.6epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the…

  • CVE-2024-22211LowJan 19, 2024
    risk 0.00cvss 3.7epss 0.01

    FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to heap-buffer overflow. This affects FreeRDP based clients. FreeRDP based server implementations and…

  • CVE-2023-7158HigDec 29, 2023
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2023-48704HigDec 22, 2023
    risk 0.00cvss 7.0epss 0.01

    ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-50246MedDec 13, 2023
    risk 0.00cvss 6.2epss 0.01

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-5686HigOct 20, 2023
    risk 0.00cvss 8.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.