Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-70122HIGHA heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a craftEPSS 0.4%CVE-2020-25712—A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerabilEPSS 0.4%CVE-2023-2763HIGHUse-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2022-44910HIGHBinbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.EPSS 0.4%CVE-2025-49727HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-55697HIGHAzure Local Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-11511HIGHIrfanView XCF Plugin XCF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-10995HIGHHeap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specifiEPSS 0.4%CVE-2025-14935HIGHNSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-70299MEDIUMA heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI EPSS 0.4%CVE-2025-11778CRITICALStack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.4%CVE-2026-81665HIGHCorosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassemblyEPSS 0.3%CVE-2026-11884MEDIUM389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculationEPSS 0.3%CVE-2026-71339MEDIUMWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-81354HIGHWindows Hello Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69449MEDIUMWindows BitLocker Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-62881MEDIUMWindows DNS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62769MEDIUMWindows DNS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-72961HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69820HIGHWindows Hello Elevation of Privilege VulnerabilityEPSS 0.3%