CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,563 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 23 of 52
- CVE-2024-37280MEDIUMCVSS 4.9EG 4.92024-06-13
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverf…
- CVE-2024-37310CRITICALCVSS 9.0EG 9.02024-07-10
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and …
- CVE-2024-37318HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37319HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37321HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37322HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37324HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37326HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37327HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37328HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37329HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37330HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37331HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37332HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37333HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37334HIGHCVSS 8.8EG 8.82024-07-09
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-37335HIGHCVSS 8.8EG 8.82024-09-10
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
- CVE-2024-3758MEDIUMCVSS 6.5EG 6.52024-05-07
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.
- CVE-2024-37601MEDIUMCVSS 4.6EG 5.12025-02-13
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of th…
- CVE-2024-37977HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37987HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-38025HIGHCVSS 7.2EG 7.22024-07-09
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
- CVE-2024-38032HIGHCVSS 7.1EG 7.12024-07-09
Microsoft Xbox Remote Code Execution Vulnerability
- CVE-2024-38045HIGHCVSS 8.1EG 8.12024-09-10
Windows TCP/IP Remote Code Execution Vulnerability
- CVE-2024-38051HIGHCVSS 7.8EG 7.82024-07-09
Windows Graphics Component Remote Code Execution Vulnerability
- CVE-2024-38054HIGHCVSS 7.8EG 7.82024-07-09
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- CVE-2024-38060HIGHCVSS 8.8EG 8.82024-07-09
Windows Imaging Component Remote Code Execution Vulnerability
- CVE-2024-38065MEDIUMCVSS 6.8EG 6.82024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-38076CRITICALCVSS 9.8EG 9.82024-07-09
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-38077CRITICALCVSS 9.8EG 9.82024-07-09
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-38079HIGHCVSS 7.8EG 7.82024-07-09
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2024-38088HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-38114HIGHCVSS 8.8EG 8.82024-08-13
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
- CVE-2024-38115HIGHCVSS 8.8EG 8.82024-08-13
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
- CVE-2024-38116HIGHCVSS 8.8EG 8.82024-08-13
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
- CVE-2024-38120HIGHCVSS 8.8EG 8.82024-08-13
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-38121HIGHCVSS 8.8EG 8.82024-08-13
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-38130HIGHCVSS 8.8EG 8.82024-08-13
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-38142HIGHCVSS 7.8EG 7.82024-08-13
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- CVE-2024-38152HIGHCVSS 7.8EG 7.82024-08-13
Windows OLE Remote Code Execution Vulnerability
- CVE-2024-38154HIGHCVSS 8.8EG 8.82024-08-13
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-38160CRITICALCVSS 9.1EG 9.12024-08-13
Windows Network Virtualization Remote Code Execution Vulnerability
- CVE-2024-38161MEDIUMCVSS 6.8EG 6.82024-08-13
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
- CVE-2024-38169HIGHCVSS 7.8EG 7.82024-08-13
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2024-38170HIGHCVSS 7.1EG 7.12024-08-13
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-38172HIGHCVSS 7.8EG 7.82024-08-13
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-38212HIGHCVSS 8.8EG 8.82024-10-08
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2024-38237HIGHCVSS 7.8EG 7.82024-09-10
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- CVE-2024-38238HIGHCVSS 7.8EG 7.82024-09-10
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- CVE-2024-38242HIGHCVSS 7.8EG 7.82024-09-10
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →