VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 59 of 160
  • CVE-2026-68848HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

  • CVE-2026-68845HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-68844HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

  • CVE-2026-68841HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-68787HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

  • CVE-2026-62810HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58600HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-58599HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

  • CVE-2026-83959HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-34674HigAug 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-77652HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a WPG_COLORMAP record, the…

  • CVE-2026-58097HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

  • CVE-2026-75769HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-75767HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-75766HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-75750HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48433HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48432HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48431HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48430HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.