CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,190)
page 89 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21804 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2023-21528 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-24551 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer underflow while parsing specially crafted PAR files. An attacker could leverage… | ||
| CVE-2023-24550 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer while parsing specially crafted PAR files. An attacker could leverage this… | ||
| CVE-2022-45491 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges. | ||
| CVE-2022-42405 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | ||
| CVE-2022-42403 | Hig | 0.51 | 7.8 | 0.01 | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | ||
| CVE-2023-0433 | Hig | 0.51 | 7.8 | 0.01 | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | ||
| CVE-2023-21605 | Hig | 0.51 | 7.8 | 0.03 | Jan 18, 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this… | ||
| CVE-2023-21594 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2023-21587 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2023-0288 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. | ||
| CVE-2022-3160 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. | ||
| CVE-2023-21793 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21792 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21791 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21790 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21787 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21786 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-21785 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2023 | 3D Builder Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.00
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer underflow while parsing specially crafted PAR files. An attacker could leverage…
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer while parsing specially crafted PAR files. An attacker could leverage this…
- risk 0.51cvss 7.8epss 0.00
Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
- risk 0.51cvss 7.8epss 0.00
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…
- risk 0.51cvss 7.8epss 0.01
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
- risk 0.51cvss 7.8epss 0.03
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…
- risk 0.51cvss 7.8epss 0.00
Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
- risk 0.51cvss 7.8epss 0.00
The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability