← Back
CWE-122

3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

JSON object

Loading...

CVEs (3,113)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
3Battery Life Diagnostic Tool
Oneapi Base ToolkitSoc Watch
Jun 17, 2026
May 12, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.
1Adobe
1Substance 3d Painter
Jun 17, 2026
May 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss...Show more
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Canon
45I Sensys Lbp621cw Firmware
I Sensys Lbp623cdw FirmwareI Sensys Lbp633cdw Firmware+42 more
Jun 17, 2026
May 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected prod...Show more
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.Show less
1Canon
45I Sensys Lbp621cw Firmware
I Sensys Lbp623cdw FirmwareI Sensys Lbp633cdw Firmware+42 more
Jun 17, 2026
May 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsiv...Show more
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.Show less
1Microsoft
1Av1 Video Extension
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
AV1 Video Extension Remote Code Execution Vulnerability
1Microsoft
10Windows 10 1507
Windows 10 1607Windows 10 1809+7 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
Windows Bluetooth Driver Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
May 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
1Siemens
1Scalance Lpe9403 Firmware
Jun 17, 2026
May 9, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup passwor...Show more
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a denial of service.Show less
1Podofo Project
1Podofo
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow....Show more
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.Show less
1Autodesk
1Fbx Software Development Kit
Jun 17, 2026
Apr 17, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.
1Adobe
1Substance 3d Designer
Jun 17, 2026
Apr 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is...Show more
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Substance 3d Designer
Jun 17, 2026
Apr 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is...Show more
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Substance 3d Stager
Jun 17, 2026
Apr 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue...Show more
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
2Fedoraproject
Imagemagick
3Extra Packages For Enterprise Linux
FedoraImagemagick
Jun 17, 2026
Apr 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-boun...Show more
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.Show less
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Word Remote Code Execution Vulnerability
1Microsoft
1Raw Image Extension
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Raw Image Extension Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Apr 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Windows Boot Manager Security Feature Bypass Vulnerability
1Microsoft
2Visual Studio 2019
Visual Studio 2022
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Visual Studio Elevation of Privilege Vulnerability
1Microsoft
5Windows Server 2008
Windows Server 2012Windows Server 2016+2 more
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Windows DNS Server Remote Code Execution Vulnerability