CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,563 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 21 of 52
- CVE-2024-28909HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28910HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28911HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28912HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28913HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28914HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28915HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28926HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28927HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28932HIGHCVSS 8.8EG 8.82024-04-09
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28935HIGHCVSS 8.8EG 8.82024-04-09
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28937HIGHCVSS 8.8EG 8.82024-04-09
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28940HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28941HIGHCVSS 8.8EG 8.82024-04-09
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-28943HIGHCVSS 8.8EG 8.82024-04-09
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29013MEDIUMCVSS 6.5EG 6.52024-06-20
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
- CVE-2024-29044HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29046HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29047HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29048HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29157CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29158HIGHCVSS 7.4EG 7.42024-05-14
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29160HIGHCVSS 7.4EG 7.42024-05-14
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29161HIGHCVSS 8.8EG 8.82024-05-14
HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29162HIGHCVSS 7.4EG 7.42024-05-14
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.
- CVE-2024-29163HIGHCVSS 7.4EG 7.42024-05-14
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29165HIGHCVSS 7.4EG 7.42024-05-14
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- CVE-2024-29204CRITICALCVSS 9.8EG 9.82024-04-19
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
- CVE-2024-29508LOWCVSS 3.3EG 3.32024-07-03
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
- CVE-2024-29982HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29983HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29984HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-29985HIGHCVSS 8.8EG 8.82024-04-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-30017HIGHCVSS 8.8EG 8.82024-05-14
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2024-30020HIGHCVSS 8.1EG 8.12024-05-14
Windows Cryptographic Services Remote Code Execution Vulnerability
- CVE-2024-30038HIGHCVSS 7.8EG 7.82024-05-14
Win32k Elevation of Privilege Vulnerability
- CVE-2024-30045MEDIUMCVSS 6.3EG 6.32024-05-14
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2024-30051CRITICALCVSS 7.8EG 9.0⚠ KEV2024-05-14
Windows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2024-30066MEDIUMCVSS 5.5EG 5.52024-06-11
Winlogon Elevation of Privilege Vulnerability
- CVE-2024-30074HIGHCVSS 8.0EG 8.02024-06-11
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
- CVE-2024-30075HIGHCVSS 8.0EG 8.02024-06-11
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
- CVE-2024-30077HIGHCVSS 8.0EG 8.02024-06-11
Windows OLE Remote Code Execution Vulnerability
- CVE-2024-30085HIGHCVSS 7.8EG 7.82024-06-11
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2024-30091HIGHCVSS 7.8EG 7.82024-06-11
Win32k Elevation of Privilege Vulnerability
- CVE-2024-30094HIGHCVSS 7.8EG 7.82024-06-11
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-30095HIGHCVSS 7.8EG 7.82024-06-11
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-3024MEDIUMCVSS 5.3EG 5.32024-03-28
A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. Attac…
- CVE-2024-30259HIGHCVSS 8.2EG 8.22024-05-14
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflo…
- CVE-2024-30288HIGHCVSS 7.8EG 7.82024-05-16
Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…
- CVE-2024-30294HIGHCVSS 7.8EG 7.82024-05-16
Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →