← Back
CWE-122

2,306 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

JSON object

Loading...

CVEs (2,306)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
5Meeting Software Development Kit
Virtual Desktop InfrastructureWorkplace+2 more
Apr 6, 2026
May 15, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Oct 28, 2025
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows DWM Core Library Elevation of Privilege Vulnerability
1Microsoft
3.net
PowershellVisual Studio 2022
Jan 8, 2025
May 14, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
.NET and Visual Studio Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jan 16, 2025
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Aug 27, 2025
May 14, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Windows Cryptographic Services Remote Code Execution Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jan 8, 2025
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Hyper-V Remote Code Execution Vulnerability
1Siemens
1Solid Edge Se2024
Mar 7, 2025
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an atta...Show more
A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.Show less
1Siemens
1Solid Edge Se2024
Mar 7, 2025
May 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an atta...Show more
A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.Show less
1Xmlsoft
1Libxml2
Nov 4, 2025
May 14, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.
1Hdfgroup
1Hdf5
Apr 18, 2025
May 14, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.