CWE-122
Heap-based Buffer Overflow
Description
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,186)
page 98 of 160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-3085 | Hig | 0.50 | 8.8 | 0.01 | Mar 16, 2026 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack… | ||
| CVE-2026-28519 | Hig | 0.50 | 8.8 | 0.00 | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing… | ||
| CVE-2025-10685 | Hig | 0.50 | — | 0.00 | Mar 16, 2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42 | ||
| CVE-2024-41147 | Hig | 0.50 | 7.7 | 0.01 | Mar 4, 2025 | An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | ||
| CVE-2024-56732 | Hig | 0.50 | 8.8 | 0.01 | Dec 27, 2024 | HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function. | ||
| CVE-2023-37329 | Hig | 0.50 | 8.8 | 0.02 | May 3, 2024 | GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but… | ||
| CVE-2023-37328 | Hig | 0.50 | 8.8 | 0.02 | May 3, 2024 | GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but… | ||
| CVE-2022-2347 | Hig | 0.50 | 7.7 | 0.01 | Sep 23, 2022 | There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts… | ||
| CVE-2020-1711 | Hig | 0.50 | 7.7 | 0.04 | Feb 11, 2020 | An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote… | ||
| CVE-2018-10893 | Hig | 0.50 | 7.6 | 0.02 | Sep 11, 2018 | Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code. | ||
| CVE-2026-11716 | Hig | 0.49 | 7.5 | 0.00 | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data. | ||
| CVE-2026-75893 | Hig | 0.49 | 7.5 | 0.00 | Sep 18, 2026 | In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths. | ||
| CVE-2026-10744 | Hig | 0.49 | 7.5 | 0.00 | Sep 18, 2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation. | ||
| CVE-2026-89028 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2026 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed… | ||
| CVE-2026-79393 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2026 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially… | ||
| CVE-2026-81355 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. | ||
| CVE-2026-77898 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73017 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | ||
| CVE-2026-69852 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | ||
| CVE-2026-69514 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
- risk 0.50cvss 8.8epss 0.01
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…
- risk 0.50cvss 8.8epss 0.00
arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing…
- risk 0.50cvss —epss 0.00
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
- risk 0.50cvss 7.7epss 0.01
An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
- risk 0.50cvss 8.8epss 0.01
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
- risk 0.50cvss 8.8epss 0.02
GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…
- risk 0.50cvss 8.8epss 0.02
GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but…
- risk 0.50cvss 7.7epss 0.01
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts…
- risk 0.50cvss 7.7epss 0.04
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote…
- risk 0.50cvss 7.6epss 0.02
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
- risk 0.49cvss 7.5epss 0.00
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
- risk 0.49cvss 7.5epss 0.00
In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg() function via IPA frame lengths.
- risk 0.49cvss 7.5epss 0.00
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
- risk 0.49cvss 7.5epss 0.01
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed…
- risk 0.49cvss 7.5epss 0.01
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially…
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
- risk 0.49cvss 7.5epss 0.01
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.