VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 65 of 160
  • CVE-2026-61930HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61926HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61923HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61359HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61355HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61353HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58651HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-54984HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

  • CVE-2026-14266HigJul 29, 2026
    risk 0.51cvss 7.8epss 0.01

    7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2026-16463HigJul 29, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2026-48372HigJul 28, 2026
    risk 0.51cvss 7.8epss 0.00

    Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48373HigJul 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48339HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48269HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-2050HigJun 24, 2026
    risk 0.51cvss 7.8epss 0.01

    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-47964HigJun 16, 2026
    risk 0.51cvss 7.8epss 0.00

    DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-12193HigJun 15, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out…

  • CVE-2026-2049HigJun 10, 2026
    risk 0.51cvss 7.8epss 0.01

    GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-48292HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48291HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.