VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,190)

page 90 of 160
  • CVE-2023-21783HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21782HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21781HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21780HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    3D Builder Remote Code Execution Vulnerability

  • CVE-2023-21738HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2023-21737HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2022-44910HigDec 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.

  • CVE-2022-2948HigDec 7, 2022
    risk 0.51cvss 7.8epss 0.00

    GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2022-4141HigNov 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

  • CVE-2022-45188HigNov 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).

  • CVE-2022-39136HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V13.3 (All versions >= V13.3.0.7 < V13.3.0.8), Teamcenter…

  • CVE-2022-2069HigOct 20, 2022
    risk 0.51cvss 7.8epss 0.00

    The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the…

  • CVE-2022-37864HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context…

  • CVE-2022-35708HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-35706HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-38433HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-38432HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-38415HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-38414HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-38413HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…