CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Ole Db Driver For Sql Server Sql Server 2019Sql Server 2022Jun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability |
1Microsoft 3Ole Db Driver For Sql Server Sql Server 2019Sql Server 2022Jun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Secure Boot Security Feature Bypass Vulnerability |
3Fedoraproject LibarchiveMicrosoft5Fedora LibarchiveWindows 11 22h2+2 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Libarchive Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Telephony Server Elevation of Privilege Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows CSC Service Elevation of Privilege Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
1Microsoft 5Windows Server 2012 Windows Server 2016Windows Server 2019+2 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 DHCP Server Service Remote Code Execution Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 DHCP Server Service Remote Code Execution Vulnerability |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Apr 9, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 9, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Secure Boot Security Feature Bypass Vulnerability |
Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User int...Show more |
Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User int...Show more |
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Apr 2, 2024 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclos...Show more |
A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-ba...Show more |
A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulatio...Show more |