CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
2,563 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 7 of 52
- CVE-2021-34313HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF file…
- CVE-2021-34317HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing PCX files.…
- CVE-2021-34326HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper val…
- CVE-2021-34327HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper val…
- CVE-2021-34328HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper val…
- CVE-2021-34329HIGHCVSS 7.8EG 7.82021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All versions < V13.2). The plmxmlAdapterSE70.dll library in affected applications lacks proper val…
- CVE-2021-34583HIGHCVSS 7.5EG 7.52021-10-26
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
- CVE-2021-34770CRITICALCVSS 10.0EG 10.02021-09-23
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute …
- CVE-2021-34871HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34893HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34896HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34900HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34904HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34905HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34907HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34938HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34945HIGHCVSS 7.8EG 7.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a …
- CVE-2021-34971HIGHCVSS 7.8EG 7.82024-05-07
Foxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is r…
- CVE-2021-36050HIGHCVSS 7.8EG 7.82021-09-01
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must …
- CVE-2021-36051HIGHCVSS 7.8EG 7.82021-10-04
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must …
- CVE-2021-36054LOWCVSS 3.3EG 3.32021-09-01
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a v…
- CVE-2021-36056MEDIUMCVSS 5.5EG 5.52021-09-01
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must …
- CVE-2021-36065HIGHCVSS 7.8EG 7.82021-09-01
Adobe Photoshop versions 21.2.10 (and earlier) and 22.4.3 (and earlier) are affected by a heap-based buffer overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…
- CVE-2021-36073HIGHCVSS 7.8EG 7.82021-09-01
Adobe Bridge version 11.1 (and earlier) is affected by a heap-based buffer overflow vulnerability when parsing a crafted .SGI file. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitat…
- CVE-2021-3625CRITICALCVSS 9.6EG 9.62021-10-05
Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363
- CVE-2021-37199HIGHCVSS 7.5EG 7.52021-10-12
A vulnerability has been identified in SINUMERIK 808D (All versions), SINUMERIK 828D (All versions < V4.95). Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to ca…
- CVE-2021-3756CRITICALCVSS 9.8EG 9.82021-10-29
libmysofa is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3770HIGHCVSS 7.8EG 7.82021-09-06
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3778HIGHCVSS 7.8EG 7.82021-09-15
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3835HIGHCVSS 8.2EG 8.22022-02-07
Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf
- CVE-2021-38404HIGHCVSS 7.8EG 7.82021-09-17
Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to e…
- CVE-2021-38415HIGHCVSS 7.8EG 7.82021-12-20
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable a heap-based buffer overflow when parsing a specially crafted project file, which may allow an attacker to execute arbitrary code.
- CVE-2021-38439CRITICALCVSS 8.6EG 9.82022-05-05
All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code.
- CVE-2021-3861HIGHCVSS 8.2EG 8.22022-02-07
The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hv…
- CVE-2021-3872HIGHCVSS 7.8EG 7.82021-10-19
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3875MEDIUMCVSS 5.5EG 5.52021-10-15
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3903HIGHCVSS 7.8EG 7.82021-10-27
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3927HIGHCVSS 7.8EG 7.82021-11-05
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3966CRITICALCVSS 9.6EG 9.62023-01-11
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
- CVE-2021-3968HIGHCVSS 8.0EG 8.02021-11-19
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-3973HIGHCVSS 7.8EG 7.82021-11-19
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-39823HIGHCVSS 7.8EG 7.82021-09-27
Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution…
- CVE-2021-3984HIGHCVSS 7.8EG 7.82021-12-01
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-39863HIGHCVSS 7.8EG 7.82021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker c…
- CVE-2021-4019HIGHCVSS 7.8EG 7.82021-12-01
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-40426HIGHCVSS 8.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a…
- CVE-2021-41253MEDIUMCVSS 5.9EG 5.92021-11-08
Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can…
- CVE-2021-4136HIGHCVSS 7.8EG 7.82021-12-19
vim is vulnerable to Heap-based Buffer Overflow
- CVE-2021-42018CRITICALCVSS 5.9EG 9.82022-03-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM …
- CVE-2021-43304HIGHCVSS 8.8EG 8.82022-03-14
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →