CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 131 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0051 | Hig | 0.00 | 7.8 | 0.01 | Jan 4, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144. | ||
| CVE-2022-23547 | Med | 0.00 | 6.5 | 0.01 | Dec 23, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer overread when parsing a certain STUN message.… | ||
| CVE-2022-23537 | Med | 0.00 | 6.5 | 0.01 | Dec 20, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The… | ||
| CVE-2022-3491 | Hig | 0.00 | 7.8 | 0.01 | Dec 3, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. | ||
| CVE-2022-3520 | Cri | 0.00 | 9.8 | 0.01 | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | ||
| CVE-2022-4141 | Hig | 0.00 | 7.8 | 0.00 | Nov 25, 2022 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. | ||
| CVE-2022-2566 | Cri | 0.00 | 9.0 | 0.01 | Sep 23, 2022 | A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a… | ||
| CVE-2022-3234 | Hig | 0.00 | 7.8 | 0.01 | Sep 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. | ||
| CVE-2022-25309 | Med | 0.00 | 5.5 | 0.00 | Sep 6, 2022 | A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option,… | ||
| CVE-2022-2991 | Med | 0.00 | 6.7 | 0.00 | Aug 25, 2022 | A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to… | ||
| CVE-2022-2849 | Hig | 0.00 | 7.8 | 0.00 | Aug 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. | ||
| CVE-2022-2819 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. | ||
| CVE-2022-2580 | Hig | 0.00 | 7.8 | 0.01 | Aug 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102. | ||
| CVE-2022-2571 | Hig | 0.00 | 7.8 | 0.00 | Aug 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101. | ||
| CVE-2022-2522 | Hig | 0.00 | 7.8 | 0.01 | Jul 25, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061. | ||
| CVE-2022-2344 | Hig | 0.00 | 7.8 | 0.01 | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045. | ||
| CVE-2022-2343 | Hig | 0.00 | 7.8 | 0.01 | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044. | ||
| CVE-2022-2284 | Hig | 0.00 | 7.8 | 0.01 | Jul 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2264 | Hig | 0.00 | 7.8 | 0.01 | Jul 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2207 | Hig | 0.00 | 7.8 | 0.01 | Jun 27, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.
- risk 0.00cvss 6.5epss 0.01
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer overread when parsing a certain STUN message.…
- risk 0.00cvss 6.5epss 0.01
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- risk 0.00cvss 7.8epss 0.00
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
- risk 0.00cvss 9.0epss 0.01
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
- risk 0.00cvss 5.5epss 0.00
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option,…
- risk 0.00cvss 6.7epss 0.00
A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to…
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.