← Back
CWE-122

3,130 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

JSON object

Loading...

CVEs (3,130)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mz Automation
1Libiec61850
Jul 9, 2026
Jun 11, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Windows OLE Remote Code Execution Vulnerability
1Microsoft
1Windows Server 2008
Jul 20, 2026
Jun 11, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
1Microsoft
1Windows Server 2008
Jul 20, 2026
Jun 11, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Winlogon Elevation of Privilege Vulnerability
1Hitachienergy
2Foxman Un
Unem
Jun 17, 2026
Jun 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a pro...Show more
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policyShow less
1Tungstenautomation
1Power Pdf
Jun 17, 2026
Jun 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User int...Show more
Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22917.Show less
1Samsung
5Exynos 1280 Firmware
Exynos 1330 FirmwareExynos 1380 Firmware+2 more
Jun 17, 2026
Jun 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->serv...Show more
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite.Show less
1Samsung
5Exynos 1280 Firmware
Exynos 1330 FirmwareExynos 1380 Firmware+2 more
Jun 17, 2026
Jun 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->inf...Show more
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead to a heap overwrite.Show less
1Libmodbus
1Libmodbus
Jun 17, 2026
May 31, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
May 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1Irontec
1Sngrep
Jun 17, 2026
May 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP pack...Show more
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet.Show less
1Libigl
1Libigl
Jun 17, 2026
May 28, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can lead to a heap buffer overflow. An attacker can provide a malicious file to trig...Show more
An out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Webmproject
1Libvpx
Jun 17, 2026
May 27, 2024
5.7 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1...Show more
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or aboveShow less
1Tp Link
1Omada Er605 Firmware
Jun 17, 2026
May 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations...Show more
TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if configured to use the Comexe DDNS service. The specific flaw exists within the handling of DNS responses. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22383.Show less