CWE-122
3,137 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,137)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attac...Show more |
A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipulation leads to heap-ba...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafte...Show more |
BT: HCI: adv_ext_report Improper discarding in adv_ext_report |
BT:Classic: Multiple missing buf length checks |
BT: Missing length checks of net_buf in rfcomm_handle_data |
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue...Show more |
After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ...Show more |
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreAug 10, 2026 Sep 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreAug 10, 2026 Sep 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreAug 10, 2026 Sep 10, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreAug 10, 2026 Sep 10, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows TCP/IP Remote Code Execution Vulnerability |
1Microsoft 5Sql 2016 Azure Connect Feature Pack Sql Server 2016Sql Server 2017+2 moreAug 10, 2026 Sep 10, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability |
1Microsoft 5Sql 2016 Azure Connect Feature Pack Sql Server 2016Sql Server 2017+2 moreAug 10, 2026 Sep 10, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreAug 10, 2026 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows TCP/IP Remote Code Execution Vulnerability |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 10, 2024 N/A· v4 2.9 LOW· v3 N/A· v2 A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` to...Show more |
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0. |
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS...Show more |
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network...Show more |