CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,190)
page 85 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49121 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2024 | A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current… | ||
| CVE-2023-47039 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe`… | ||
| CVE-2023-21740 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2023 | Windows Media Remote Code Execution Vulnerability | ||
| CVE-2023-41140 | Hig | 0.51 | 7.8 | 0.00 | Nov 23, 2023 | A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current… | ||
| CVE-2023-47056 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2023 | Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… | ||
| CVE-2023-47042 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2023 | Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2023-36408 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2023-36730 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36598 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2023-36417 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-43787 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2023 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. | ||
| CVE-2023-38143 | Hig | 0.51 | 7.8 | 0.04 | Sep 12, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-36793 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36772 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-36771 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-36770 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-36740 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Viewer Remote Code Execution Vulnerability | ||
| CVE-2023-36739 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Viewer Remote Code Execution Vulnerability | ||
| CVE-2023-38076 | Hig | 0.51 | 7.8 | 0.00 | Sep 12, 2023 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All… | ||
| CVE-2023-38071 | Hig | 0.51 | 7.8 | 0.00 | Sep 12, 2023 | A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All… |
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current…
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe`…
- risk 0.51cvss 7.8epss 0.01
Windows Media Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…
- risk 0.51cvss 7.8epss 0.00
Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…
- risk 0.51cvss 7.8epss 0.00
Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
- risk 0.51cvss 7.8epss 0.04
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Viewer Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Viewer Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All…