CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploited when the application processes specially crafted project files. |
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing the RSLinx Classic ap...Show more |
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code. |
4Canonical DebianHaxx+1 more4Debian Linux Enterprise LinuxLibcurl+1 moreNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large tem...Show more |
An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow. |
3Debian Jasper ProjectRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. |
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2. |
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Jul 31, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a mali...Show more |
4Citrix DebianQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Jul 27, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is perf...Show more |
3Debian RedhatSpice Project7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible c...Show more |
3Advancemame CanonicalDebian3Advancecomp Debian LinuxUbuntu LinuxNov 21, 2024 Jul 27, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into proc...Show more |
An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d...Show more |
An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxNov 21, 2024 Jul 16, 2018 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image. |
4Canonical DebianLinux+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jun 20, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from ps...Show more |
1Deltaww 1Delta Industrial Automation Dopsoft Nov 21, 2024 Jun 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to...Show more |
1Siemens 9Rfid 181 Eip Firmware Ruggedcom Wimax FirmwareScalance X200 Firmware+6 moreNov 21, 2024 Jun 14, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fa...Show more |
In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution. |
3Canonical DebianProcps Ng Project3Debian Linux Procps NgUbuntu LinuxNov 21, 2024 May 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw i...Show more |