CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. |
2Debian Eprosima2Debian Linux Fast DdsJun 17, 2026 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID...Show more |
2Debian Eprosima2Debian Linux Fast DdsJun 17, 2026 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_L...Show more |
Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti...Show more |
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overfl...Show more |
HEVC Video Extensions Remote Code Execution Vulnerability |
1Microsoft 2Windows 10 1809 Windows Server 2019Jun 17, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreAug 10, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Excel Remote Code Execution Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelAug 10, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Visio Remote Code Execution Vulnerability |
1Zoom 3Rooms Virtual Desktop InfrastructureZoomJun 17, 2026 Aug 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Aug 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_he...Show more |
2Fedoraproject Procps Project2Fedora ProcpsJun 17, 2026 Aug 2, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap. |
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to...Show more |
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attac...Show more |
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attac...Show more |
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issue...Show more |
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execut...Show more |
1Honeywell 4Direct Station Engineering StationExperion Server+1 moreJun 17, 2026 Jul 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message |
Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These...Show more |
Paint 3D Remote Code Execution Vulnerability |