VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 2 of 135
  • CVE-2026-24822CriJan 27, 2026
    risk 0.65cvss epss 0.00

    Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.

  • CVE-2025-47981CriJul 8, 2025
    risk 0.65cvss 9.8epss 0.25

    Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

  • CVE-2025-23123CriMay 19, 2025
    risk 0.65cvss 10.0epss 0.01

    A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow vulnerability in the UniFi Protect Cameras (Version 4.75.43 and earlier) firmware.

  • CVE-2024-37080CriJun 18, 2024
    risk 0.65cvss 9.8epss 0.12

    vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

  • CVE-2023-45318CriFeb 20, 2024
    risk 0.65cvss 10.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-4911HigKEVOct 3, 2023
    risk 0.65cvss 7.8epss 0.81

    A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID…

  • CVE-2023-21692CriFeb 14, 2023
    risk 0.65cvss 9.8epss 0.21

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-34819CriJul 12, 2022
    risk 0.65cvss 10.0epss 0.02

    A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46),…

  • CVE-2021-21940CriOct 12, 2021
    risk 0.65cvss 10.0epss 0.01

    A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-34770CriSep 23, 2021
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative…

  • CVE-2019-14901CriNov 29, 2019
    risk 0.65cvss 9.8epss 0.17

    A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with…

  • CVE-2019-18240CriNov 13, 2019
    risk 0.65cvss 9.8epss 0.14

    In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-15679CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity.

  • CVE-2019-15678CriOct 29, 2019
    risk 0.65cvss 9.8epss 0.12

    TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity.

  • CVE-2019-5482CriSep 16, 2019
    risk 0.65cvss 9.8epss 0.18

    Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

  • CVE-2026-65791CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67873CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…

  • CVE-2026-47291CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.23

    Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

  • CVE-2026-45657CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.15

    Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

  • CVE-2026-8175CriMay 27, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be…