CWE-122
2,306 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (2,306)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreSep 17, 2024 Sep 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 18, 2024 Sep 10, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows TCP/IP Remote Code Execution Vulnerability |
1Microsoft 5Sql 2016 Azure Connect Feature Pack Sql Server 2016Sql Server 2017+2 moreSep 23, 2024 Sep 10, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability |
1Microsoft 5Sql 2016 Azure Connect Feature Pack Sql Server 2016Sql Server 2017+2 moreSep 23, 2024 Sep 10, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 20, 2024 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows TCP/IP Remote Code Execution Vulnerability |
2Opensc Project Redhat2Enterprise Linux OpenscNov 3, 2025 Sep 10, 2024 N/A· v4 2.9 LOW· v3 N/A· v2 A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` to...Show more |
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0. |
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS...Show more |
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network...Show more |
Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become...Show more |
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security...Show more |
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security...Show more |
Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. |
Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in the typeahead buffer but does not check whether there is enough space left in the buffer to han...Show more |
Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf)...Show more |
Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium) |
Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreAug 29, 2024 Aug 14, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreSep 4, 2024 Aug 14, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. |
1Zoom 6Meeting Software Development Kit RoomsRooms Controller+3 moreSep 4, 2024 Aug 14, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. |