CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 67 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38154 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-36896 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2023-36865 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2023-2763 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2023 | Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute… | ||
| CVE-2023-35374 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Paint 3D Remote Code Execution Vulnerability | ||
| CVE-2023-35363 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-35337 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-35305 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-35304 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-32047 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2023 | Paint 3D Remote Code Execution Vulnerability | ||
| CVE-2023-37247 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files.… | ||
| CVE-2023-37246 | Hig | 0.51 | 7.8 | 0.00 | Jul 11, 2023 | A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PRT files.… | ||
| CVE-2023-34432 | Hig | 0.51 | 7.8 | 0.00 | Jul 10, 2023 | A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. | ||
| CVE-2023-34318 | Hig | 0.51 | 7.8 | 0.00 | Jul 10, 2023 | A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. | ||
| CVE-2023-27390 | Hig | 0.51 | 7.8 | 0.01 | Jul 5, 2023 | A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-32028 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-32027 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32026 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32025 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-24897 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute…
- risk 0.51cvss 7.8epss 0.01
Paint 3D Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Paint 3D Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files.…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PRT files.…
- risk 0.51cvss 7.8epss 0.00
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
- risk 0.51cvss 7.8epss 0.00
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
- risk 0.51cvss 7.8epss 0.01
A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability