VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 157 of 160
  • CVE-2023-34474MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a…

  • CVE-2023-3291LowJun 16, 2023
    risk 0.00cvss 3.3epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.

  • CVE-2023-2804MedMay 25, 2023
    risk 0.00cvss 6.5epss 0.01

    A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range,…

  • CVE-2023-2241MedApr 22, 2023
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has…

  • CVE-2023-1906MedApr 12, 2023
    risk 0.00cvss 5.5epss 0.01

    A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting…

  • CVE-2023-1655HigMar 27, 2023
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.

  • CVE-2023-27585HigMar 14, 2023
    risk 0.00cvss 7.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is…

  • CVE-2023-0866HigFeb 16, 2023
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-0841MedFeb 15, 2023
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3_dmx_process of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The…

  • CVE-2023-0819HigFeb 13, 2023
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.

  • CVE-2023-0760HigFeb 9, 2023
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.

  • CVE-2023-0051HigJan 4, 2023
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.

  • CVE-2022-23547MedDec 23, 2022
    risk 0.00cvss 6.5epss 0.01

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer overread when parsing a certain STUN message.…

  • CVE-2022-23537MedDec 20, 2022
    risk 0.00cvss 6.5epss 0.01

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The…

  • CVE-2022-3491HigDec 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

  • CVE-2022-3520CriDec 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

  • CVE-2022-2566CriSep 23, 2022
    risk 0.00cvss 9.0epss 0.01

    A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a…

  • CVE-2022-3234HigSep 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

  • CVE-2022-25309MedSep 6, 2022
    risk 0.00cvss 5.5epss 0.01

    A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option,…

  • CVE-2022-2991MedAug 25, 2022
    risk 0.00cvss 6.7epss 0.00

    A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to…