VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 93 of 135
  • CVE-2025-20774MedDec 2, 2025
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID:…

  • CVE-2025-63701MedNov 14, 2025
    risk 0.44cvss 6.8epss 0.00

    A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized output buffer. The driver incorrectly assumes the output buffer size…

  • CVE-2025-20741MedNov 4, 2025
    risk 0.44cvss 6.7epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422;…

  • CVE-2025-5517MedOct 20, 2025
    risk 0.44cvss 6.8epss 0.00

    Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB Terra AC wallbox (MID/ CE) -Terra AC Juno CE, ABB Terra AC wallbox (MID/ CE) -Terra AC PTB, ABB Terra AC wallbox (JP).This…

  • CVE-2025-36902MedSep 4, 2025
    risk 0.44cvss 6.7epss 0.00

    In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-54630MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-48071HigJul 31, 2025
    risk 0.44cvss 7.8epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep…

  • CVE-2025-4657MedJul 17, 2025
    risk 0.44cvss 6.7epss 0.00

    A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.

  • CVE-2024-0145MedFeb 12, 2025
    risk 0.44cvss 6.8epss 0.01

    NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to code execution and data tampering.

  • CVE-2024-43526MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43525MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43523MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-20517MedOct 2, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-20516MedOct 2, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-6258MedSep 13, 2024
    risk 0.44cvss 6.8epss 0.00

    BT: Missing length checks of net_buf in rfcomm_handle_data

  • CVE-2024-38161MedAug 13, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-38065MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-6154MedJun 20, 2024
    risk 0.44cvss 6.7epss 0.00

    Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged…

  • CVE-2024-27374MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead…

  • CVE-2024-27372MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead…