CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerabilit...Show more |
A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow when a maliciously crafted project file is run by the system. |
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value. |
6Apple CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Server+11 moreMay 6, 2026 May 20, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbit...Show more |
6Apple CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 Mar 24, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. |
5Adobe HpOpensuse+2 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreApr 21, 2026 Jun 23, 2015 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec...Show more |
Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wi...Show more |
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which triggers a heap-based b...Show more |
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a crafted image,...Show more |
1Schneider Electric 5Opc Factory Server Tlxcdlfofs Opc Factory Server TlxcdltofsOpc Factory Server Tlxcdluofs+2 moreMay 6, 2026 Apr 4, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, T...Show more |
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets. |
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, po...Show more |
1Adobe 3Acrobat Acrobat ReaderReaderMay 21, 2026 Oct 13, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as e...Show more |