CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Ge PtcRockwellautomation+1 more7Industrial Gateway Server Kepserver EnterpriseKepware Kepserverex+4 moreJun 17, 2026 Jan 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway S...Show more |
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of PCX files. This...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of JT files. This...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of RGB and SGI fil...Show more |
1Siemens 65Scalance X200 4pirt Firmware Scalance X201 3pirt FirmwareScalance X202 2irt Firmware+62 moreJun 17, 2026 Jan 12, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The web server...Show more |
1Siemens 65Scalance X200 4pirt Firmware Scalance X201 3pirt FirmwareScalance X202 2irt Firmware+62 moreJun 17, 2026 Jan 12, 2021 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraOpenjpeg+1 moreJun 17, 2026 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greate...Show more |
1Panorama 1Nhiservisignadapter Jun 17, 2026 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. |
2Redhat X.org2Enterprise Linux X ServerJun 17, 2026 Dec 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and i...Show more |
1Medtronic 1Mycarelink Smart Model 25000 Firmware Jun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Medtronic MyCareLink Smart 25000 is vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software...Show more |
A heap-based buffer overflow vulnerability exists within the WECON LeviStudioU Release Build 2019-09-21 and prior when processing project files. Opening a specially crafted project file could allow an attacker to exploit...Show more |
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to a...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to ha...Show more |
TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is pr...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on in the routine. The pa...Show more |
2Fedoraproject Imagemagick2Fedora ImagemagickJun 17, 2026 Dec 8, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. Th...Show more |
A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files. A specially crafted malformed file can trigger a heap overflow which can result in out of bounds me...Show more |
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jump...Show more |