VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 144 of 160
  • CVE-2024-4323CriMay 20, 2024
    risk 0.02cvss 9.8epss 0.27

    A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

  • CVE-2022-43634CriMar 29, 2023
    risk 0.02cvss 9.8epss 0.19

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit function. The issue results from the lack of proper…

  • CVE-2022-0572HigFeb 14, 2022
    risk 0.02cvss 7.8epss 0.26

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2026-50518CriJul 14, 2026
    risk 0.01cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

  • CVE-2022-0714MedFeb 22, 2022
    risk 0.01cvss 5.5epss 0.13

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.

  • CVE-2021-32626HigOct 4, 2021
    risk 0.01cvss 7.5epss 0.16

    Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and…

  • CVE-2018-8800CriFeb 5, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.

  • CVE-2018-8797CriFeb 5, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.

  • CVE-2018-8793CriFeb 5, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.

  • CVE-2026-13307MedJul 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not…

  • CVE-2026-67191CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.01

    Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's…

  • CVE-2026-56165CriJul 24, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

  • CVE-2026-61390HigJul 22, 2026
    risk 0.00cvss 7.7epss 0.00

    There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

  • CVE-2026-13473HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or…

  • CVE-2026-44251MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the…

  • CVE-2026-40106MedJul 17, 2026
    risk 0.00cvss 4.7epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When expanding registry paths…

  • CVE-2026-34150HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager's analysis engine, causing…

  • CVE-2026-15449MedJul 16, 2026
    risk 0.00cvss —epss 0.00

    A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_ioc_prop_common() in usr/src/uts/common/io/dld/dld_drv.c copies the dld_ioc_macprop_t ioctl header in…

  • CVE-2026-15422CriJul 16, 2026
    risk 0.00cvss —epss 0.01

    The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote,…

  • CVE-2026-47471HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.