CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,563 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 17 of 52
- CVE-2023-43787HIGHCVSS 7.8EG 7.82023-10-10
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
- CVE-2023-44418HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-X3260 Prog.cgi Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication …
- CVE-2023-44428HIGHCVSS 7.8EG 7.82024-05-03
MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required to exploit…
- CVE-2023-44429HIGHCVSS 8.8EG 8.82024-05-03
GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is requi…
- CVE-2023-44441HIGHCVSS 7.8EG 7.82024-05-03
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vuln…
- CVE-2023-44442HIGHCVSS 7.8EG 8.52024-05-03
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vuln…
- CVE-2023-4504HIGHCVSS 7.0EG 7.02023-09-21
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, …
- CVE-2023-45318CRITICALCVSS 10.0EG 10.02024-02-20
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious pac…
- CVE-2023-45591HIGHCVSS 7.5EG 7.52024-03-05
A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in the context of the binary. This may result in…
- CVE-2023-46256CRITICALCVSS 9.8EG 9.82023-10-31
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfun…
- CVE-2023-46426HIGHCVSS 8.8EG 8.82024-03-09
Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c.
- CVE-2023-4682MEDIUMCVSS 5.5EG 5.92023-08-31
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
- CVE-2023-4692HIGHCVSS 7.8EG 7.82023-10-25
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack m…
- CVE-2023-47038HIGHCVSS 7.8EG 7.82023-12-18
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
- CVE-2023-47039HIGHCVSS 7.8EG 7.82024-01-02
A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl atte…
- CVE-2023-47042HIGHCVSS 7.8EG 7.82023-11-16
Adobe Media Encoder version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…
- CVE-2023-47051HIGHCVSS 7.8EG 7.82023-11-16
Adobe Audition version 24.0 (and earlier) and 23.6.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ…
- CVE-2023-47056HIGHCVSS 7.8EG 7.82023-11-16
Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue re…
- CVE-2023-47118CRITICALCVSS 9.8EG 9.82023-12-20
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially cra…
- CVE-2023-4738HIGHCVSS 7.8EG 7.82023-09-02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- CVE-2023-47455CRITICALCVSS 9.1EG 9.12023-11-07
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
- CVE-2023-4751HIGHCVSS 7.8EG 7.82023-09-03
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- CVE-2023-4781HIGHCVSS 7.8EG 7.82023-09-05
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
- CVE-2023-48263HIGHCVSS 8.1EG 8.12024-01-10
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.
- CVE-2023-48704HIGHCVSS 7.5EG 7.52023-12-22
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially craft…
- CVE-2023-4911CRITICALCVSS 7.8EG 9.0⚠ KEV2023-10-03
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables …
- CVE-2023-49121HIGHCVSS 7.8EG 7.82024-01-09
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to exe…
- CVE-2023-49122HIGHCVSS 7.8EG 7.82024-01-09
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to exe…
- CVE-2023-49123HIGHCVSS 7.8EG 7.82024-01-09
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to exe…
- CVE-2023-49501HIGHCVSS 8.0EG 8.02024-04-19
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
- CVE-2023-49528HIGHCVSS 8.0EG 8.02024-04-12
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
- CVE-2023-49600HIGHCVSS 8.1EG 8.12024-05-28
An out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerabil…
- CVE-2023-50009HIGHCVSS 8.0EG 8.02024-04-19
FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
- CVE-2023-50229HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required…
- CVE-2023-50230HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required…
- CVE-2023-50246MEDIUMCVSS 5.5EG 5.52023-12-13
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
- CVE-2023-50364MEDIUMCVSS 6.4EG 6.42024-04-26
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already …
- CVE-2023-50739HIGHCVSS 8.8EG 8.82025-01-18
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2023-50806HIGHCVSS 8.4EG 8.42024-07-09
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850 Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380 Exynos 13…
- CVE-2023-51596HIGHCVSS 7.1EG 7.12024-05-03
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required…
- CVE-2023-51794HIGHCVSS 7.8EG 7.82024-04-26
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.
- CVE-2023-51795HIGHCVSS 8.0EG 8.02024-04-19
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
- CVE-2023-52168HIGHCVSS 8.4EG 8.42024-07-03
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11…
- CVE-2023-52356HIGHCVSS 7.5EG 7.52024-01-25
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
- CVE-2023-5344HIGHCVSS 7.5EG 7.52023-10-02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
- CVE-2023-5400HIGHCVSS 8.1EG 8.12024-04-17
Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notifica…
- CVE-2023-5404HIGHCVSS 8.1EG 8.12024-04-17
Server receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-5460MEDIUMCVSS 5.7EG 5.72023-10-09
A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. …
- CVE-2023-5568MEDIUMCVSS 6.5EG 6.52023-10-25
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
- CVE-2023-5686HIGHCVSS 8.8EG 8.82023-10-20
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →