VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 87 of 135
  • CVE-2026-32177HigMay 12, 2026
    risk 0.47cvss 7.3epss 0.01

    Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-32149HigApr 14, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2026-29022HigMar 3, 2026
    risk 0.47cvss 7.3epss 0.00

    dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between…

  • CVE-2025-14905HigFeb 23, 2026
    risk 0.47cvss 7.2epss 0.01

    A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting…

  • CVE-2026-21247HigFeb 10, 2026
    risk 0.47cvss 7.3epss 0.01

    Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2026-24925HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-15247HigDec 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue is the function snap7_rs::client::S7Client::download of the file client.rs. Such manipulation leads to heap-based buffer overflow. The attack can be executed…

  • CVE-2025-14673HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit…

  • CVE-2025-14672HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-59504HigNov 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

  • CVE-2024-50571HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0…

  • CVE-2025-9951HigSep 9, 2025
    risk 0.47cvss epss 0.00

    A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

  • CVE-2025-36907HigSep 4, 2025
    risk 0.47cvss 7.3epss 0.00

    In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution privileges needed. User…

  • CVE-2025-50161HigAug 12, 2025
    risk 0.47cvss 7.3epss 0.01

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49666HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.

  • CVE-2025-48797HigMay 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

  • CVE-2025-46333HigApr 25, 2025
    risk 0.47cvss epss 0.00

    z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, and higher-level operations when the anti-aliasing mode is set to `.default` (such as…

  • CVE-2025-31344HigApr 14, 2025
    risk 0.47cvss 7.3epss 0.00

    Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.

  • CVE-2025-29069HigApr 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding…

  • CVE-2024-49089HigDec 12, 2024
    risk 0.47cvss 7.2epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability