VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 87 of 160
  • CVE-2023-27390HigJul 5, 2023
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-32028HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft SQL OLE DB Remote Code Execution Vulnerability

  • CVE-2023-32027HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-32026HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-32025HigJun 16, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-24897HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-33146HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2023-29370HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Media Remote Code Execution Vulnerability

  • CVE-2023-34488HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.01

    NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.

  • CVE-2023-24014HigJun 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2023-29344HigJun 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2023-29283HigMay 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-29341HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.01

    AV1 Video Extension Remote Code Execution Vulnerability

  • CVE-2023-27911HigApr 17, 2023
    risk 0.51cvss 7.8epss 0.01

    A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.

  • CVE-2023-26416HigApr 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-26413HigApr 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-26394HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-28292HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Raw Image Extension Remote Code Execution Vulnerability

  • CVE-2023-28262HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Visual Studio Elevation of Privilege Vulnerability

  • CVE-2023-28225HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows NTLM Elevation of Privilege Vulnerability