VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 61 of 135
  • CVE-2024-8587HigOct 29, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of…

  • CVE-2024-47964HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of…

  • CVE-2024-45143HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-45139HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-47417HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2024-43560HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.03

    Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

  • CVE-2024-43528HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

  • CVE-2024-43527HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-38261HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-41981HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted BDF files. This could…

  • CVE-2024-46264HigOct 1, 2024
    risk 0.51cvss 7.8epss 0.00

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

  • CVE-2024-7674HigSep 30, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

  • CVE-2024-7673HigSep 30, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

  • CVE-2024-7018HigSep 23, 2024
    risk 0.51cvss 7.8epss 0.00

    Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2024-43756HigSep 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-39380HigSep 13, 2024
    risk 0.51cvss 7.8epss 0.00

    After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-38242HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.03

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-38238HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-38237HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.03

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-42851HigAug 27, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.