CWE-122
2,251 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (2,251)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. |
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release. |
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` functi...Show more |
heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service. |
yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (...Show more |
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647. |
Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6. |
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. |
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreNov 21, 2024 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. |
Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Explo...Show more |
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreNov 21, 2024 Feb 22, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. |
2Fedoraproject Radare2Fedora Radare2Nov 21, 2024 Feb 22, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. |
2Fedoraproject Radare2Fedora Radare2Nov 21, 2024 Feb 22, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. |
2Fedoraproject Mariadb2Fedora MariadbNov 21, 2024 Feb 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is requi...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malici...Show more |
1Bentley 3Microstation Microstation ConnectViewNov 21, 2024 Feb 18, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target mus...Show more |