CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,190)
page 87 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27390 | Hig | 0.51 | 7.8 | 0.01 | Jul 5, 2023 | A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-32028 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-32027 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32026 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32025 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-24897 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-33146 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2023-29370 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | Windows Media Remote Code Execution Vulnerability | ||
| CVE-2023-34488 | Hig | 0.51 | 7.8 | 0.01 | Jun 12, 2023 | NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages. | ||
| CVE-2023-24014 | Hig | 0.51 | 7.8 | 0.00 | Jun 7, 2023 | Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code. | ||
| CVE-2023-29344 | Hig | 0.51 | 7.8 | 0.01 | Jun 5, 2023 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2023-29283 | Hig | 0.51 | 7.8 | 0.00 | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-29341 | Hig | 0.51 | 7.8 | 0.01 | May 9, 2023 | AV1 Video Extension Remote Code Execution Vulnerability | ||
| CVE-2023-27911 | Hig | 0.51 | 7.8 | 0.01 | Apr 17, 2023 | A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. | ||
| CVE-2023-26416 | Hig | 0.51 | 7.8 | 0.00 | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-26413 | Hig | 0.51 | 7.8 | 0.00 | Apr 13, 2023 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-26394 | Hig | 0.51 | 7.8 | 0.00 | Apr 12, 2023 | Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-28292 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2023 | Raw Image Extension Remote Code Execution Vulnerability | ||
| CVE-2023-28262 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2023-28225 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | Windows NTLM Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.01
A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Media Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
- risk 0.51cvss 7.8epss 0.00
Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.01
AV1 Video Extension Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
- risk 0.51cvss 7.8epss 0.00
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.01
Raw Image Extension Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Visual Studio Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows NTLM Elevation of Privilege Vulnerability