CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 132 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2182 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2125 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2061 | Low | 0.00 | 3.3 | 0.00 | Jun 13, 2022 | Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0. | ||
| CVE-2022-31003 | Cri | 0.00 | 9.1 | 0.04 | May 31, 2022 | Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil… | ||
| CVE-2022-1942 | Hig | 0.00 | 7.8 | 0.02 | May 31, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1886 | Hig | 0.00 | 7.8 | 0.01 | May 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1733 | Hig | 0.00 | 7.8 | 0.01 | May 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968. | ||
| CVE-2022-1621 | Hig | 0.00 | 7.8 | 0.02 | May 10, 2022 | Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-1619 | Hig | 0.00 | 7.8 | 0.03 | May 8, 2022 | Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution | ||
| CVE-2022-1437 | Hig | 0.00 | 7.1 | 0.01 | Apr 22, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. | ||
| CVE-2022-1383 | Med | 0.00 | 6.1 | 0.01 | Apr 18, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. | ||
| CVE-2022-1381 | Hig | 0.00 | 7.8 | 0.03 | Apr 18, 2022 | global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-1286 | Cri | 0.00 | 9.8 | 0.01 | Apr 10, 2022 | heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | ||
| CVE-2022-1253 | Cri | 0.00 | 9.8 | 0.02 | Apr 6, 2022 | Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release. | ||
| CVE-2022-1240 | Hig | 0.00 | 7.8 | 0.01 | Apr 6, 2022 | Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable.… | ||
| CVE-2022-1244 | Med | 0.00 | 5.5 | 0.01 | Apr 5, 2022 | heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service. | ||
| CVE-2022-1160 | Hig | 0.00 | 7.8 | 0.01 | Mar 30, 2022 | heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647. | ||
| CVE-2022-1052 | Med | 0.00 | 5.5 | 0.00 | Mar 24, 2022 | Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2022-1061 | Hig | 0.00 | 7.5 | 0.01 | Mar 24, 2022 | Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. | ||
| CVE-2021-23165 | Cri | 0.00 | 9.8 | 0.04 | Mar 16, 2022 | A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. |
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 3.3epss 0.00
Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.
- risk 0.00cvss 9.1epss 0.04
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil…
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
- risk 0.00cvss 7.8epss 0.02
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 7.8epss 0.03
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
- risk 0.00cvss 7.1epss 0.01
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
- risk 0.00cvss 6.1epss 0.01
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
- risk 0.00cvss 7.8epss 0.03
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 9.8epss 0.01
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- risk 0.00cvss 9.8epss 0.02
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
- risk 0.00cvss 7.8epss 0.01
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable.…
- risk 0.00cvss 5.5epss 0.01
heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.
- risk 0.00cvss 7.8epss 0.01
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
- risk 0.00cvss 5.5epss 0.00
Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 7.5epss 0.01
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.
- risk 0.00cvss 9.8epss 0.04
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.