CWE-122
2,244 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (2,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Bareos Debian2Bareos Debian LinuxNov 21, 2024 Jul 10, 2020 N/A· v4 7.4 HIGH· v3 6.0 MEDIUM· v2 In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify...Show more |
Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause t...Show more |
In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fixed in 1.0.1. |
1Siemens 4Simatic Pcs 7 Simatic Process Device ManagerSimatic Step 7+1 moreNov 21, 2024 Jun 10, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SI...Show more |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remot...Show more |
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable ph...Show more |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a m...Show more |
Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small. |
1Emerson 1Openenterprise Scada Server Nov 21, 2024 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially...Show more |
4Debian OpensuseQemu+1 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Bloc...Show more |
2Broadcom Synology2Bcm4339 Firmware Router ManagerNov 21, 2024 Feb 3, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case sce...Show more |
2Broadcom Synology2Bcm4339 Firmware Router ManagerNov 21, 2024 Feb 3, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the wor...Show more |
1Philips 1Hue Bridge V2 Firmware Nov 21, 2024 Jan 23, 2020 N/A· v4 7.9 HIGH· v3 4.3 MEDIUM· v2 Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution. |
2Broadcom Linux2Brcmfmac Driver Linux KernelNov 21, 2024 Jan 16, 2020 N/A· v4 8.3 HIGH· v3 7.9 HIGH· v2 The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can...Show more |
2Opensuse Tigervnc2Leap TigervncNov 21, 2024 Dec 26, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of...Show more |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack ap...Show more |
2Opensuse Tigervnc2Leap TigervncNov 21, 2024 Dec 26, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result int...Show more |
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can...Show more |
1Siemens 1Sppa T3000 Ms3000 Migration Server Nov 21, 2024 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could cause a Denial-of-Service condition and potentially gain remote code ex...Show more |
1Siemens 1Sppa T3000 Ms3000 Migration Server Nov 21, 2024 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code exec...Show more |