CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 61 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8587 | Hig | 0.51 | 7.8 | 0.00 | Oct 29, 2024 | A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of… | ||
| CVE-2024-47964 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of… | ||
| CVE-2024-45143 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-45139 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-47417 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-43560 | Hig | 0.51 | 7.8 | 0.03 | Oct 8, 2024 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-43528 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2024-43527 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-38261 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-41981 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted BDF files. This could… | ||
| CVE-2024-46264 | Hig | 0.51 | 7.8 | 0.00 | Oct 1, 2024 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h. | ||
| CVE-2024-7674 | Hig | 0.51 | 7.8 | 0.00 | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process. | ||
| CVE-2024-7673 | Hig | 0.51 | 7.8 | 0.00 | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process. | ||
| CVE-2024-7018 | Hig | 0.51 | 7.8 | 0.00 | Sep 23, 2024 | Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) | ||
| CVE-2024-43756 | Hig | 0.51 | 7.8 | 0.00 | Sep 13, 2024 | Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-39380 | Hig | 0.51 | 7.8 | 0.00 | Sep 13, 2024 | After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-38242 | Hig | 0.51 | 7.8 | 0.03 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38238 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38237 | Hig | 0.51 | 7.8 | 0.03 | Sep 10, 2024 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-42851 | Hig | 0.51 | 7.8 | 0.00 | Aug 27, 2024 | Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. |
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of…
- risk 0.51cvss 7.8epss 0.00
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.03
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted BDF files. This could…
- risk 0.51cvss 7.8epss 0.00
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
- risk 0.51cvss 7.8epss 0.00
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.03
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.03
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.