CWE-122
2,524 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (2,524)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution. |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to...Show more |
7Canonical DebianFedoraproject+4 more12A700s Firmware Active Iq Unified Manager For Vmware VsphereCn1610 Firmware+9 moreJun 17, 2026 Jun 3, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. |
7Debian F5Fedoraproject+4 more11Debian Linux Enterprise Manager Ops CenterFedora+8 moreJun 17, 2026 May 28, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
1Whatsapp 2Whatsapp Whatsapp BusinessJun 17, 2026 May 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134,...Show more |
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary...Show more |
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code...Show more |
1Deltaww 1Cncsoft Screeneditor Jun 17, 2026 Apr 17, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacke...Show more |
1Honeywell 1Experion Process Knowledge System Nov 21, 2024 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remot...Show more |
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability. |
2Siemens Uvnc4Sinumerik Access Mymachine/p2p Sinumerik Pcu Base Win10 Software/ipcSinumerik Pcu Base Win7 Software/ipc+1 moreJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack appears to be exploitable via network con...Show more |
2Siemens Uvnc4Sinumerik Access Mymachine/p2p Sinumerik Pcu Base Win10 Software/ipcSinumerik Pcu Base Win7 Software/ipc+1 moreJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack appears to be exploitable via network c...Show more |
2Siemens Uvnc4Sinumerik Access Mymachine/p2p Sinumerik Pcu Base Win10 Software/ipcSinumerik Pcu Base Win7 Software/ipc+1 moreJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code execution. This attack appears to be exploitable via network connectivity...Show more |
1Rainbowpdf 1Office Server Document Converter Jun 17, 2026 Mar 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, t...Show more |
2Siemens Uvnc4Sinumerik Access Mymachine/p2p Sinumerik Pcu Base Win10 Software/ipcSinumerik Pcu Base Win7 Software/ipc+1 moreJun 17, 2026 Mar 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vul...Show more |
2Siemens Uvnc4Sinumerik Access Mymachine/p2p Sinumerik Pcu Base Win10 Software/ipcSinumerik Pcu Base Win7 Software/ipc+1 moreJun 17, 2026 Mar 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revisi...Show more |
Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael Samson working with Tr...Show more |
3Debian OpensuseRdesktop3Debian Linux LeapRdesktopJun 17, 2026 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution. |
3Debian OpensuseRdesktop3Debian Linux LeapRdesktopJun 17, 2026 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution. |
3Debian OpensuseRdesktop3Debian Linux LeapRdesktopJun 17, 2026 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution. |