CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 152 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49175 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49172 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-49164 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-48564 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-42990 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42975 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-15520 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires… | ||
| CVE-2026-15506 | Hig | 0.00 | 7.8 | 0.00 | Jul 12, 2026 | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The… | ||
| CVE-2026-54001 | Hig | 0.00 | — | 0.00 | Jul 10, 2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode table targeting a maliciously crafted… | ||
| CVE-2026-54000 | Hig | 0.00 | — | 0.00 | Jul 10, 2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted… | ||
| CVE-2026-15182 | Med | 0.00 | 5.3 | 0.00 | Jul 9, 2026 | A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been… | ||
| CVE-2026-58306 | Med | 0.00 | 6.1 | 0.00 | Jul 9, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98. | ||
| CVE-2026-56645 | Hig | 0.00 | 8.8 | 0.01 | Jul 3, 2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-14427 | Hig | 0.00 | 8.3 | 0.00 | Jul 1, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14415 | Hig | 0.00 | 8.8 | 0.00 | Jul 1, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-14385 | Hig | 0.00 | 8.8 | 0.00 | Jul 1, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-20462 | Med | 0.00 | 6.7 | 0.00 | Jul 1, 2026 | In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID:… | ||
| CVE-2026-51219 | Hig | 0.00 | 7.5 | 0.01 | Jun 29, 2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload. | ||
| CVE-2026-51218 | Hig | 0.00 | 7.5 | 0.01 | Jun 29, 2026 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | ||
| CVE-2026-13590 | Med | 0.00 | 5.6 | 0.01 | Jun 29, 2026 | A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. The manipulation of the argument length results in heap-based buffer… |
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.01
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.00cvss 5.3epss 0.00
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires…
- risk 0.00cvss 7.8epss 0.00
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The…
- risk 0.00cvss —epss 0.00
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode table targeting a maliciously crafted…
- risk 0.00cvss —epss 0.00
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted…
- risk 0.00cvss 5.3epss 0.00
A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been…
- risk 0.00cvss 6.1epss 0.00
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.
- risk 0.00cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.3epss 0.00
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 8.8epss 0.00
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
- risk 0.00cvss 8.8epss 0.00
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 6.7epss 0.00
In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID:…
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- risk 0.00cvss 5.6epss 0.01
A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. The manipulation of the argument length results in heap-based buffer…