VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (2,687)

page 97 of 135
  • CVE-2025-40930HigSep 8, 2025
    risk 0.42cvss 7.5epss 0.01

    JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact.

  • CVE-2025-57803HigAug 26, 2025
    risk 0.42cvss 7.5epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride)…

  • CVE-2025-55004HigAug 13, 2025
    risk 0.42cvss 7.6epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in…

  • CVE-2024-42648MedJul 14, 2025
    risk 0.42cvss 6.5epss 0.00

    NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

  • CVE-2025-32990MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory…

  • CVE-2025-49670MedJul 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-53184MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53183MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53182MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53181MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53180MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53179MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-45029MedJul 2, 2025
    risk 0.42cvss 6.5epss 0.00

    WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cgi.

  • CVE-2024-20522MedOct 2, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS)…

  • CVE-2024-45993MedSep 30, 2024
    risk 0.42cvss 6.5epss 0.00

    Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

  • CVE-2024-42438MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-42437MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-42436MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-38950MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

  • CVE-2024-38949MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc