VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 66 of 135
  • CVE-2023-47056HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2023-47042HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-36408HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2023-36730HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-36598HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-36417HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft SQL OLE DB Remote Code Execution Vulnerability

  • CVE-2023-43787HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

  • CVE-2023-38143HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-36793HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-36772HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36771HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36770HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36740HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2023-36739HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2023-38076HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…

  • CVE-2023-38071HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…

  • CVE-2023-4781HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

  • CVE-2023-40031HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing…

  • CVE-2023-38212HigAug 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-38170HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    HEVC Video Extensions Remote Code Execution Vulnerability