Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-24283HIGHMultiple UNC Provider Kernel Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-3463MEDIUMGE Digital CIMPLICITY Heap-based Buffer OverflowEPSS 0.4%CVE-2023-47056HIGHZDI-CAN-21763: Adobe Premiere Pro MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-5750HIGHWOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-21337MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2026-3082HIGHGStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-76886HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.4%CVE-2023-39492HIGHPDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-47051MEDIUMZDI-CAN-21683: Adobe Audition MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-6361HIGHHeap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage EPSS 0.4%CVE-2024-22058HIGHA buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated EPSS 0.4%CVE-2024-39392HIGHAdobe Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-61390HIGHThere is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunctiEPSS 0.4%CVE-2024-52996HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-49705HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-52995HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-5477HIGHSony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-5479HIGHSony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-1275HIGHJPG File Parsing Heap-Based Overflow VulnerabilityEPSS 0.4%