CWE-122
2,244 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (2,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Panorama 1Nhiservisignadapter Nov 21, 2024 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. |
2Redhat X.org2Enterprise Linux X ServerNov 21, 2024 Dec 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and i...Show more |
1Medtronic 1Mycarelink Smart Model 25000 Firmware May 22, 2025 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Medtronic MyCareLink Smart 25000 is vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software...Show more |
A heap-based buffer overflow vulnerability exists within the WECON LeviStudioU Release Build 2019-09-21 and prior when processing project files. Opening a specially crafted project file could allow an attacker to exploit...Show more |
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to a...Show more |
2Debian Imagemagick2Debian Linux ImagemagickNov 21, 2024 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to ha...Show more |
TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is pr...Show more |
2Debian Imagemagick2Debian Linux ImagemagickNov 21, 2024 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on in the routine. The pa...Show more |
2Fedoraproject Imagemagick2Fedora ImagemagickNov 21, 2024 Dec 8, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. Th...Show more |
A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files. A specially crafted malformed file can trigger a heap overflow which can result in out of bounds me...Show more |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jump...Show more |
WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code execution. |
1Rockwellautomation 1Factorytalk Linx Nov 21, 2024 Nov 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the l...Show more |
1Rockwellautomation 1Factorytalk Linx Nov 21, 2024 Nov 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code exec...Show more |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in...Show more |
A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD files. A specially crafted malformed file can trigger a heap overflow, which can result in remote co...Show more |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompression heap overflow. |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in...Show more |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. An instance exists in USDC file format FIELDSETS section decompression heap overflow. |
2Apple Pixar3Ipados Iphone OsOpenusdNov 21, 2024 Nov 13, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in the USDC file format FIELDS section decompression heap overflow. |