CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 70 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42403 | Hig | 0.51 | 7.8 | 0.01 | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | ||
| CVE-2023-21605 | Hig | 0.51 | 7.8 | 0.03 | Jan 18, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this… | ||
| CVE-2023-21594 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2023-21587 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2022-3160 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. | ||
| CVE-2023-21793 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21792 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21791 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21790 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21787 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21786 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21785 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21783 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21782 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21781 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21780 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21738 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2023-21737 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2022-44910 | Hig | 0.51 | 7.8 | 0.00 | Dec 14, 2022 | Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c. | ||
| CVE-2022-2948 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code. |
- risk 0.51cvss 7.8epss 0.01
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…
- risk 0.51cvss 7.8epss 0.03
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
- risk 0.51cvss 7.8epss 0.00
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.