VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 58 of 135
  • CVE-2025-21390HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2025-21375HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2025-21123HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-22880HigFeb 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…

  • CVE-2023-40222HigFeb 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary…

  • CVE-2025-21139HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-21137HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-21129HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-21395HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Access Remote Code Execution Vulnerability

  • CVE-2025-21382HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2025-21378HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Windows CSC Service Elevation of Privilege Vulnerability

  • CVE-2025-21356HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2025-21186HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Access Remote Code Execution Vulnerability

  • CVE-2024-13051HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this…

  • CVE-2024-13050HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this…

  • CVE-2024-12670HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-12669HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-12179HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-52059HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0…

  • CVE-2024-49072HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Task Scheduler Elevation of Privilege Vulnerability