CWE-122
3,113 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CVEs (3,113)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4365 Apps Microsoft 365Office 2021+1 moreJun 19, 2026 Jun 9, 2026 N/A· v4 3.3 LOW· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 7365 Apps Microsoft 365Office 2016+4 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 7365 Apps Microsoft 365Office 2016+4 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Remote Desktop Client Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 23h2+5 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 29, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 23h2+5 moreJun 17, 2026 Jun 9, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service,...Show more |
A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer...Show more |
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability. |
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade...Show more |
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgra...Show more |
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue. |
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types and presenting a set of parameters to the affected interf...Show more |