CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (2,687)
page 94 of 135| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31036 | Med | 0.44 | 6.8 | 0.00 | Apr 22, 2024 | A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams. | ||
| CVE-2024-26168 | Med | 0.44 | 6.8 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-21341 | Med | 0.44 | 6.8 | 0.01 | Feb 13, 2024 | Windows Kernel Remote Code Execution Vulnerability | ||
| CVE-2023-33221 | Med | 0.44 | 6.8 | 0.01 | Dec 15, 2023 | When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is… | ||
| CVE-2023-20081 | Med | 0.44 | 6.8 | 0.01 | Mar 23, 2023 | A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service… | ||
| CVE-2023-21694 | Med | 0.44 | 6.8 | 0.01 | Feb 14, 2023 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2022-34454 | Med | 0.44 | 6.7 | 0.00 | Feb 10, 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters. | ||
| CVE-2022-1892 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2022-1891 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2022-1890 | Med | 0.44 | 6.7 | 0.00 | Jan 26, 2023 | A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | ||
| CVE-2021-31986 | Med | 0.44 | 6.8 | 0.01 | Oct 5, 2021 | User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage. | ||
| CVE-2021-28211 | Med | 0.44 | 6.7 | 0.00 | Jun 11, 2021 | A heap overflow in LzmaUefiDecompressGetInfo function in EDK II. | ||
| CVE-2016-8654 | Hig | 0.44 | 7.8 | 0.02 | Aug 1, 2018 | A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. | ||
| CVE-2016-1834 | Hig | 0.44 | 7.8 | 0.05 | May 20, 2016 | Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)… | ||
| CVE-2026-25749 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When… | ||
| CVE-2025-51089 | Med | 0.43 | 6.5 | 0.05 | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow. | ||
| CVE-2025-5915 | Med | 0.43 | 6.6 | 0.00 | Jun 9, 2025 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated… | ||
| CVE-2025-31164 | Med | 0.43 | 6.6 | 0.00 | Mar 28, 2025 | heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. | ||
| CVE-2025-21256 | Med | 0.43 | 6.6 | 0.01 | Jan 14, 2025 | Windows Digital Media Elevation of Privilege Vulnerability | ||
| CVE-2024-49094 | Med | 0.43 | 6.6 | 0.01 | Dec 12, 2024 | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability |
- risk 0.44cvss 6.8epss 0.00
A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams.
- risk 0.44cvss 6.8epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Kernel Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.01
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is…
- risk 0.44cvss 6.8epss 0.01
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service…
- risk 0.44cvss 6.8epss 0.01
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.00
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.7epss 0.00
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- risk 0.44cvss 6.8epss 0.01
User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow resulting in crashes and data leakage.
- risk 0.44cvss 6.7epss 0.00
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
- risk 0.44cvss 7.8epss 0.02
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
- risk 0.44cvss 7.8epss 0.05
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
- risk 0.43cvss 6.6epss 0.00
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When…
- risk 0.43cvss 6.5epss 0.05
Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.
- risk 0.43cvss 6.6epss 0.00
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated…
- risk 0.43cvss 6.6epss 0.00
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.
- risk 0.43cvss 6.6epss 0.01
Windows Digital Media Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability