CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 90 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-58725 | Hig | 0.46 | 7.0 | 0.00 | Oct 14, 2025 | Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-30402 | Hig | 0.46 | 8.1 | 0.00 | Jul 11, 2025 | A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f | ||
| CVE-2025-49727 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-1252 | Hig | 0.46 | 7.1 | 0.00 | May 8, 2025 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from… | ||
| CVE-2025-27478 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21414 | Hig | 0.46 | 7.0 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2025-21184 | Hig | 0.46 | 7.0 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2024-43522 | Hig | 0.46 | 7.0 | 0.00 | Oct 8, 2024 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | ||
| CVE-2024-38170 | Hig | 0.46 | 7.1 | 0.01 | Aug 13, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-38032 | Hig | 0.46 | 7.1 | 0.01 | Jul 9, 2024 | Microsoft Xbox Remote Code Execution Vulnerability | ||
| CVE-2023-51596 | Hig | 0.46 | 7.1 | 0.01 | May 3, 2024 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that… | ||
| CVE-2024-33429 | Hig | 0.46 | 7.1 | 0.01 | May 1, 2024 | Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file. | ||
| CVE-2024-0156 | Hig | 0.46 | 7.0 | 0.00 | Mar 4, 2024 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. | ||
| CVE-2022-36764 | Hig | 0.46 | 7.0 | 0.00 | Jan 9, 2024 | EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | ||
| CVE-2022-36763 | Hig | 0.46 | 7.0 | 0.00 | Jan 9, 2024 | EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. | ||
| CVE-2023-47118 | Hig | 0.46 | 7.0 | 0.00 | Dec 20, 2023 | ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface… | ||
| CVE-2023-47038 | Hig | 0.46 | 7.0 | 0.01 | Dec 18, 2023 | A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer. | ||
| CVE-2023-4264 | Hig | 0.46 | 7.1 | 0.01 | Sep 27, 2023 | Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem. | ||
| CVE-2023-4504 | Hig | 0.46 | 7.0 | 0.01 | Sep 21, 2023 | Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023. | ||
| CVE-2023-21406 | Hig | 0.46 | 7.1 | 0.00 | Jul 25, 2023 | Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid… |
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 8.1epss 0.00
A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.00
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from…
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Xbox Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…
- risk 0.46cvss 7.1epss 0.01
Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.
- risk 0.46cvss 7.0epss 0.00
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.
- risk 0.46cvss 7.0epss 0.00
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
- risk 0.46cvss 7.0epss 0.00
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
- risk 0.46cvss 7.0epss 0.00
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…
- risk 0.46cvss 7.0epss 0.01
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
- risk 0.46cvss 7.1epss 0.01
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
- risk 0.46cvss 7.0epss 0.01
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
- risk 0.46cvss 7.1epss 0.00
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid…