VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 62 of 135
  • CVE-2024-41853HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-41850HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-38172HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-38169HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2024-38152HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2024-38142HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

  • CVE-2024-7546HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7545HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7544HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7543HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-39392HigAug 2, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20785HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20783HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20781HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-38079HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2024-38051HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Remote Code Execution Vulnerability

  • CVE-2024-23155HigJun 25, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current…

  • CVE-2024-23154HigJun 25, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the…

  • CVE-2024-37001HigJun 25, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the…

  • CVE-2024-30095HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability