VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 83 of 160
  • CVE-2023-42038HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-39494HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor OXPS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability…

  • CVE-2023-39492HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in…

  • CVE-2023-38090HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF popUpMenu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-38080HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-37344HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-37342HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-37335HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-35709HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-34299HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability…

  • CVE-2023-34289HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-51794HigApr 26, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

  • CVE-2024-26256HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.85

    Libarchive Remote Code Execution Vulnerability

  • CVE-2024-26239HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Telephony Server Elevation of Privilege Vulnerability

  • CVE-2024-26229HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.09

    Windows CSC Service Elevation of Privilege Vulnerability

  • CVE-2024-26211HigApr 9, 2024
    risk 0.51cvss 7.8epss 0.04

    Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

  • CVE-2024-27341HigApr 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2024-27340HigApr 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that…

  • CVE-2024-21913HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software by overstepping the memory boundaries, which triggers an access violation. Once inside, the…

  • CVE-2024-1848HigMar 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024. These…