VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 89 of 160
  • CVE-2023-21804HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2023-21528HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2023-24551HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer underflow while parsing specially crafted PAR files. An attacker could leverage…

  • CVE-2023-24550HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application is vulnerable to heap-based buffer while parsing specially crafted PAR files. An attacker could leverage this…

  • CVE-2022-45491HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.

  • CVE-2022-42405HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2022-42403HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2023-0433HigJan 21, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

  • CVE-2023-21605HigJan 18, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…

  • CVE-2023-21594HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2023-21587HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2023-0288HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

  • CVE-2022-3160HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

  • CVE-2023-21793HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21792HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21791HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21790HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21787HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21786HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21785HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability