VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 85 of 160
  • CVE-2023-49121HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current…

  • CVE-2023-47039HigJan 2, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe`…

  • CVE-2023-21740HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Media Remote Code Execution Vulnerability

  • CVE-2023-41140HigNov 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2023-47056HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2023-47042HigNov 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-36408HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2023-36730HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-36598HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-36417HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft SQL OLE DB Remote Code Execution Vulnerability

  • CVE-2023-43787HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

  • CVE-2023-38143HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-36793HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-36772HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36771HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36770HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-36740HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2023-36739HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2023-38076HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…

  • CVE-2023-38071HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…