VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 88 of 135
  • CVE-2024-37041HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…

  • CVE-2024-38025HigJul 9, 2024
    risk 0.47cvss 7.2epss 0.02

    Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability

  • CVE-2024-21778HigJul 8, 2024
    risk 0.47cvss 7.2epss 0.01

    A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this…

  • CVE-2024-26202HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    DHCP Server Service Remote Code Execution Vulnerability

  • CVE-2024-26195HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.02

    DHCP Server Service Remote Code Execution Vulnerability

  • CVE-2024-2212HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.01

    In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap…

  • CVE-2024-22453HigMar 19, 2024
    risk 0.47cvss 7.2epss 0.00

    Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.

  • CVE-2023-6779HigJan 31, 2024
    risk 0.47cvss 8.2epss 0.03

    An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an…

  • CVE-2023-35350HigJul 11, 2023
    risk 0.47cvss 7.2epss 0.01

    Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability

  • CVE-2023-30763HigMay 12, 2023
    risk 0.47cvss 7.2epss 0.00

    Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-28254HigApr 11, 2023
    risk 0.47cvss 7.2epss 0.01

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2023-23400HigMar 14, 2023
    risk 0.47cvss 7.2epss 0.01

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2021-25495HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25479HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-21572HigJun 24, 2021
    risk 0.47cvss 7.2epss 0.00

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

  • CVE-2026-62753HigAug 11, 2026
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50472HigAug 11, 2026
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

  • CVE-2026-18497HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed…

  • CVE-2026-10849HigAug 3, 2026
    risk 0.46cvss 8.2epss 0.00

    The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a…

  • CVE-2026-16118HigJul 17, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the…