VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 67 of 135
  • CVE-2023-38154HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-36896HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2023-36865HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2023-2763HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute…

  • CVE-2023-35374HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Paint 3D Remote Code Execution Vulnerability

  • CVE-2023-35363HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-35337HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-35305HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-35304HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-32047HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Paint 3D Remote Code Execution Vulnerability

  • CVE-2023-37247HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files.…

  • CVE-2023-37246HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PRT files.…

  • CVE-2023-34432HigJul 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.

  • CVE-2023-34318HigJul 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.

  • CVE-2023-27390HigJul 5, 2023
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-32028HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft SQL OLE DB Remote Code Execution Vulnerability

  • CVE-2023-32027HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-32026HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-32025HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-24897HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability