CWE-122
3,138 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,138)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Telephony Service Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Telephony Service Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Telephony Service Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Telephony Service Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Telephony Service Remote Code Execution Vulnerability |
LightGBM Remote Code Execution Vulnerability |
1Microsoft 3Sql Server 2016 Sql Server 2017Sql Server 2019Jun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client Remote Code Execution Vulnerability |
1Microsoft 3Sql Server 2016 Sql Server 2017Sql Server 2019Jun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Server Native Client Remote Code Execution Vulnerability |
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700. |
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_su...Show more |
A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial...Show more |
1Autodesk 8Autocad Autocad Advance SteelAutocad Architecture+5 moreJun 17, 2026 Oct 29, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive da...Show more |
1Autodesk 8Autocad Autocad Advance SteelAutocad Architecture+5 moreJun 17, 2026 Oct 29, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write se...Show more |
1Autodesk 8Advance Steel AutocadAutocad Architecture+5 moreJun 17, 2026 Oct 29, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sen...Show more |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leve...Show more |
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ...Show more |
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ...Show more |