VYPR

CWE-122

Heap-based Buffer Overflow

VariantDraftLikelihood: High

Description

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,186)

page 98 of 160
  • CVE-2026-3085HigMar 16, 2026
    risk 0.50cvss 8.8epss 0.01

    GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2026-28519HigMar 16, 2026
    risk 0.50cvss 8.8epss 0.00

    arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing…

  • CVE-2025-10685HigMar 16, 2026
    risk 0.50cvss —epss 0.00

    Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42

  • CVE-2024-41147HigMar 4, 2025
    risk 0.50cvss 7.7epss 0.01

    An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-56732HigDec 27, 2024
    risk 0.50cvss 8.8epss 0.01

    HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.

  • CVE-2023-37329HigMay 3, 2024
    risk 0.50cvss 8.8epss 0.02

    GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…

  • CVE-2023-37328HigMay 3, 2024
    risk 0.50cvss 8.8epss 0.02

    GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…

  • CVE-2022-2347HigSep 23, 2022
    risk 0.50cvss 7.7epss 0.01

    There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts…

  • CVE-2020-1711HigFeb 11, 2020
    risk 0.50cvss 7.7epss 0.04

    An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote…

  • CVE-2018-10893HigSep 11, 2018
    risk 0.50cvss 7.6epss 0.02

    Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

  • CVE-2026-11716HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

  • CVE-2026-75893HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

  • CVE-2026-10744HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

  • CVE-2026-89028HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed…

  • CVE-2026-79393HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially…

  • CVE-2026-81355HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.

  • CVE-2026-77898HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

  • CVE-2026-73017HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

  • CVE-2026-69852HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

  • CVE-2026-69514HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.