CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 19 of 66
- CVE-2024-21349HIGHCVSS 8.8EG 8.82024-02-13
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
- CVE-2024-21345HIGHCVSS 8.8EG 8.82024-02-13
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-25448HIGHCVSS 8.8EG 8.82024-02-09
An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.
- CVE-2023-35639HIGHCVSS 8.8EG 8.82023-12-12
Microsoft ODBC Driver Remote Code Execution Vulnerability
- CVE-2023-35630HIGHCVSS 8.8EG 8.82023-12-12
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
- CVE-2023-36423HIGHCVSS 8.8EG 8.82023-11-14
Microsoft Remote Registry Service Remote Code Execution Vulnerability
- CVE-2023-36402HIGHCVSS 8.8EG 8.82023-11-14
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-36400HIGHCVSS 8.8EG 8.82023-11-14
Windows HMAC Key Derivation Elevation of Privilege Vulnerability
- CVE-2023-5686HIGHCVSS 8.8EG 8.82023-10-20
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
- CVE-2023-36577HIGHCVSS 8.8EG 8.82023-10-10
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-38147HIGHCVSS 8.8EG 8.82023-09-12
Windows Miracast Wireless Display Remote Code Execution Vulnerability
- CVE-2023-4353HIGHCVSS 8.8EG 8.82023-08-15
Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-2905HIGHCVSS 8.8EG 8.82023-08-09
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability …
- CVE-2023-35302HIGHCVSS 8.8EG 8.82023-07-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-29372HIGHCVSS 8.8EG 8.82023-06-14
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-29362HIGHCVSS 8.8EG 8.82023-06-14
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2023-2137HIGHCVSS 8.8EG 8.82023-04-19
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-28275HIGHCVSS 8.8EG 8.82023-04-11
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-28240HIGHCVSS 8.8EG 8.82023-04-11
Windows Network Load Balancing Remote Code Execution Vulnerability
- CVE-2023-28231HIGHCVSS 8.8EG 8.82023-04-11
DHCP Server Service Remote Code Execution Vulnerability
- CVE-2023-24928HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24926HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-21727HIGHCVSS 8.8EG 8.82023-04-11
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2022-43648HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the …
- CVE-2022-24672HIGHCVSS 8.8EG 8.82023-03-28
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2023-24913HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24907HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24876HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24868HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24867HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-23406HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-23403HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-21799HIGHCVSS 8.8EG 8.82023-02-14
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-21695HIGHCVSS 8.8EG 8.82023-02-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- CVE-2022-43591HIGHCVSS 8.8EG 8.82023-01-12
A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application w…
- CVE-2022-2915HIGHCVSS 8.8EG 8.82022-08-26
A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.…
- CVE-2022-32137HIGHCVSS 8.8EG 8.82022-06-24
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.
- CVE-2021-40426HIGHCVSS 8.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a…
- CVE-2021-21947HIGHCVSS 8.8EG 8.82022-04-14
Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a maliciou…
- CVE-2021-21946HIGHCVSS 8.8EG 8.82022-04-14
Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a maliciou…
- CVE-2021-21945HIGHCVSS 8.8EG 8.82022-04-14
Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulne…
- CVE-2021-21944HIGHCVSS 8.8EG 8.82022-04-14
Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulne…
- CVE-2021-21943HIGHCVSS 8.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
- CVE-2021-21942HIGHCVSS 8.8EG 8.82022-04-14
An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to remote code execution. An attacker can provide a malicious file to trigger this vuln…
- CVE-2021-21914HIGHCVSS 8.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnera…
- CVE-2021-43305HIGHCVSS 8.8EG 8.82022-03-14
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(…
- CVE-2021-43304HIGHCVSS 8.8EG 8.82022-03-14
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(…
- CVE-2021-20043HIGHCVSS 8.8EG 8.82021-12-08
A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 a…
- CVE-2021-28558HIGHCVSS 8.8EG 8.82021-09-02
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Heap-based buffer overflow vulnerability in the PDFLibTool component. An unauthenticated att…
- CVE-2021-31439HIGHCVSS 8.8EG 8.82021-05-21
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the proc…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →