VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 91 of 135
  • CVE-2023-33152HigJul 11, 2023
    risk 0.46cvss 7.0epss 0.01

    Microsoft ActiveX Remote Code Execution Vulnerability

  • CVE-2023-28218HigApr 11, 2023
    risk 0.46cvss 7.0epss 0.12

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2023-22660HigApr 5, 2023
    risk 0.46cvss 7.0epss 0.01

    A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To…

  • CVE-2022-34400HigFeb 1, 2023
    risk 0.46cvss 7.1epss 0.00

    Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.

  • CVE-2023-21733HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Bind Filter Driver Elevation of Privilege Vulnerability

  • CVE-2022-31144HigJul 19, 2022
    risk 0.46cvss 7.0epss 0.03

    Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is…

  • CVE-2020-13600HigMay 25, 2021
    risk 0.46cvss 7.0epss 0.00

    Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr

  • CVE-2020-27752HigDec 8, 2020
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an…

  • CVE-2018-1165HigFeb 21, 2018
    risk 0.46cvss 7.0epss 0.01

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…

  • CVE-2016-1762HigMar 24, 2016
    risk 0.46cvss 8.1epss 0.06

    The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

  • CVE-2026-21399MedAug 11, 2026
    risk 0.45cvss epss 0.00

    Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low…

  • CVE-2026-52834higJul 2, 2026
    risk 0.45cvss epss

    ### Summary On 32-bit platforms, decoding a crafted image may lead to out-of-bounds writes due to integer overflow in length calculation. ### Details & PoC The test listed below fail under miri with command `cargo +nightly miri test --release -p jxl-grid` Or you can use…

  • CVE-2026-24922MedFeb 6, 2026
    risk 0.45cvss 6.9epss 0.00

    Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-65079MedFeb 3, 2026
    risk 0.45cvss epss 0.00

    A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

  • CVE-2020-25687MedJan 20, 2021
    risk 0.45cvss 5.9epss 0.87

    A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a…

  • CVE-2020-25683MedJan 20, 2021
    risk 0.45cvss 5.9epss 0.86

    A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a…

  • CVE-2026-70330MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70304MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65799MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65797MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.