VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 90 of 135
  • CVE-2025-58725HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30402HigJul 11, 2025
    risk 0.46cvss 8.1epss 0.00

    A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f

  • CVE-2025-49727HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1252HigMay 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from…

  • CVE-2025-27478HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21414HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2025-21184HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2024-43522HigOct 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

  • CVE-2024-38170HigAug 13, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-38032HigJul 9, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Xbox Remote Code Execution Vulnerability

  • CVE-2023-51596HigMay 3, 2024
    risk 0.46cvss 7.1epss 0.01

    BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that…

  • CVE-2024-33429HigMay 1, 2024
    risk 0.46cvss 7.1epss 0.01

    Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.

  • CVE-2024-0156HigMar 4, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.

  • CVE-2022-36764HigJan 9, 2024
    risk 0.46cvss 7.0epss 0.00

    EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

  • CVE-2022-36763HigJan 9, 2024
    risk 0.46cvss 7.0epss 0.00

    EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

  • CVE-2023-47118HigDec 20, 2023
    risk 0.46cvss 7.0epss 0.00

    ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-47038HigDec 18, 2023
    risk 0.46cvss 7.0epss 0.01

    A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.

  • CVE-2023-4264HigSep 27, 2023
    risk 0.46cvss 7.1epss 0.01

    Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

  • CVE-2023-4504HigSep 21, 2023
    risk 0.46cvss 7.0epss 0.01

    Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

  • CVE-2023-21406HigJul 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid…