VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 81 of 160
  • CVE-2024-38242HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.03

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-38238HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-38237HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.03

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-42851HigAug 27, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

  • CVE-2024-41853HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-41850HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-38172HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-38169HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2024-38152HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2024-38142HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

  • CVE-2024-7546HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7545HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7544HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-7543HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to…

  • CVE-2024-39392HigAug 2, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20785HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20783HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-20781HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2024-38079HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2024-38051HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Remote Code Execution Vulnerability