VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 69 of 135
  • CVE-2023-25885HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2023-25883HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2023-25882HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2023-25874HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-25872HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-25868HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-25864HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-22236HigFeb 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2023-23782HigFeb 16, 2023
    risk 0.51cvss 7.8epss 0.00

    A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to…

  • CVE-2023-23381HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-23390HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-23378HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Print 3D Remote Code Execution Vulnerability

  • CVE-2023-23377HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21812HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.04

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-21804HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2023-21528HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2023-24551HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer underflow while parsing specially crafted PAR files. An attacker could leverage…

  • CVE-2023-24550HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer while parsing specially crafted PAR files. An attacker could leverage this…

  • CVE-2022-45491HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.

  • CVE-2022-42405HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…