VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 154 of 160
  • CVE-2025-29769MedApr 7, 2025
    risk 0.00cvss 5.5epss 0.00

    libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally within libvips as…

  • CVE-2025-3159MedApr 3, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads…

  • CVE-2025-2849LowMar 27, 2025
    risk 0.00cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The…

  • CVE-2025-30216CriMar 25, 2025
    risk 0.00cvss 9.4epss 0.03

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow…

  • CVE-2025-2592MedMar 21, 2025
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack…

  • CVE-2025-29912CriMar 17, 2025
    risk 0.00cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer…

  • CVE-2025-1788MedMar 1, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in rizinorg rizin up to 0.8.0. This affects the function rz_utf8_encode in the library /librz/util/utf8.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has…

  • CVE-2024-55627MedJan 6, 2025
    risk 0.00cvss 5.9epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an…

  • CVE-2024-45306MedSep 2, 2024
    risk 0.00cvss 4.5epss 0.00

    Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we…

  • CVE-2024-43790MedAug 22, 2024
    risk 0.00cvss 4.5epss 0.00

    Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf). When right-left mode (:set rl) is enabled, the search…

  • CVE-2024-32671CriJul 29, 2024
    risk 0.00cvss 9.8epss 0.00

    Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

  • CVE-2024-32664MedMay 7, 2024
    risk 0.00cvss 5.3epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19.…

  • CVE-2024-34408MedMay 3, 2024
    risk 0.00cvss 5.3epss 0.00

    Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.

  • CVE-2023-50230HigMay 3, 2024
    risk 0.00cvss 8.0epss 0.01

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-50229HigMay 3, 2024
    risk 0.00cvss 8.0epss 0.02

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-50009HigApr 19, 2024
    risk 0.00cvss 8.0epss 0.00

    FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

  • CVE-2024-31582HigApr 17, 2024
    risk 0.00cvss 7.8epss 0.00

    FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.

  • CVE-2024-24335HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

  • CVE-2024-24334HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

  • CVE-2024-28231CriMar 20, 2024
    risk 0.00cvss 9.6epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the…