CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 62 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-41853 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2024 | InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-41850 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2024 | InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-38172 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-38169 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2024-38152 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2024-38142 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2024-7546 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2024 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to… | ||
| CVE-2024-7545 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2024 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to… | ||
| CVE-2024-7544 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2024 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to… | ||
| CVE-2024-7543 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2024 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to… | ||
| CVE-2024-39392 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2024 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-20785 | Hig | 0.51 | 7.8 | 0.00 | Jul 9, 2024 | InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-20783 | Hig | 0.51 | 7.8 | 0.00 | Jul 9, 2024 | InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-20781 | Hig | 0.51 | 7.8 | 0.00 | Jul 9, 2024 | InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-38079 | Hig | 0.51 | 7.8 | 0.01 | Jul 9, 2024 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2024-38051 | Hig | 0.51 | 7.8 | 0.01 | Jul 9, 2024 | Windows Graphics Component Remote Code Execution Vulnerability | ||
| CVE-2024-23155 | Hig | 0.51 | 7.8 | 0.00 | Jun 25, 2024 | A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current… | ||
| CVE-2024-23154 | Hig | 0.51 | 7.8 | 0.00 | Jun 25, 2024 | A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the… | ||
| CVE-2024-37001 | Hig | 0.51 | 7.8 | 0.00 | Jun 25, 2024 | A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the… | ||
| CVE-2024-30095 | Hig | 0.51 | 7.8 | 0.01 | Jun 11, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows OLE Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…
- risk 0.51cvss 7.8epss 0.00
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…
- risk 0.51cvss 7.8epss 0.00
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…
- risk 0.51cvss 7.8epss 0.00
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the…
- risk 0.51cvss 7.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability