CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 130 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5344 | Hig | 0.00 | 7.5 | 0.01 | Oct 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969. | ||
| CVE-2023-4751 | Hig | 0.00 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-4738 | Hig | 0.00 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2023-4682 | Med | 0.00 | 5.5 | 0.00 | Aug 31, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-4322 | Cri | 0.00 | 9.8 | 0.01 | Aug 14, 2023 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | ||
| CVE-2023-2905 | Hig | 0.00 | 8.8 | 0.01 | Aug 9, 2023 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version… | ||
| CVE-2023-34474 | Med | 0.00 | 5.5 | 0.00 | Jun 16, 2023 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a… | ||
| CVE-2023-3291 | Low | 0.00 | 3.3 | 0.00 | Jun 16, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2. | ||
| CVE-2023-2804 | Med | 0.00 | 6.5 | 0.01 | May 25, 2023 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range,… | ||
| CVE-2023-2241 | Med | 0.00 | 5.3 | 0.00 | Apr 22, 2023 | A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has… | ||
| CVE-2023-1906 | Med | 0.00 | 5.5 | 0.01 | Apr 12, 2023 | A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting… | ||
| CVE-2023-1655 | Hig | 0.00 | 7.8 | 0.01 | Mar 27, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0. | ||
| CVE-2023-27585 | Hig | 0.00 | 7.5 | 0.02 | Mar 14, 2023 | PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is… | ||
| CVE-2023-1170 | Med | 0.00 | 6.6 | 0.00 | Mar 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | ||
| CVE-2023-0866 | Hig | 0.00 | 7.8 | 0.00 | Feb 16, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV. | ||
| CVE-2023-0841 | Med | 0.00 | 6.3 | 0.01 | Feb 15, 2023 | A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3_dmx_process of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The… | ||
| CVE-2023-0819 | Hig | 0.00 | 7.8 | 0.00 | Feb 13, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV. | ||
| CVE-2023-0760 | Hig | 0.00 | 7.8 | 0.00 | Feb 9, 2023 | Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. | ||
| CVE-2023-0433 | Hig | 0.00 | 7.8 | 0.01 | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | ||
| CVE-2023-0288 | Hig | 0.00 | 7.8 | 0.00 | Jan 13, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. |
- risk 0.00cvss 7.5epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.00cvss 5.5epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
- risk 0.00cvss 8.8epss 0.01
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…
- risk 0.00cvss 5.5epss 0.00
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a…
- risk 0.00cvss 3.3epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
- risk 0.00cvss 6.5epss 0.01
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range,…
- risk 0.00cvss 5.3epss 0.00
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has…
- risk 0.00cvss 5.5epss 0.01
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
- risk 0.00cvss 7.5epss 0.02
PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is…
- risk 0.00cvss 6.6epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- risk 0.00cvss 6.3epss 0.01
A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3_dmx_process of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The…
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.