VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 92 of 135
  • CVE-2026-62886HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-62883MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62881MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62871HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-62769MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62699MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-70638HigAug 6, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer…

  • CVE-2026-47747HigJun 16, 2026
    risk 0.44cvss 7.8epss 0.00

    stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in…

  • CVE-2026-47749HigJun 16, 2026
    risk 0.44cvss 7.8epss 0.00

    stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files.…

  • CVE-2026-47311HigMay 19, 2026
    risk 0.44cvss 7.8epss 0.00

    Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

  • CVE-2026-42046HigMay 11, 2026
    risk 0.44cvss 7.8epss 0.00

    libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format.…

  • CVE-2026-5405HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

  • CVE-2026-5403HigMay 1, 2026
    risk 0.44cvss 7.8epss 0.00

    SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

  • CVE-2026-32223MedApr 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-33298HigMar 24, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a…

  • CVE-2026-3082HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.01

    GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-2920HigMar 16, 2026
    risk 0.44cvss 7.8epss 0.01

    GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-27940HigMar 12, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past…

  • CVE-2026-24288MedMar 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-20876MedJan 13, 2026
    risk 0.44cvss 6.7epss 0.01

    Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.