Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-20742HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2026-16118HIGHXdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.cEPSS 0.3%CVE-2025-54211HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-69878MEDIUMWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-73017HIGHGraphics Kernel Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-30299HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-34318HIGHHeap-buffer-overflow in src/hcom.cEPSS 0.3%CVE-2023-41140—A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicEPSS 0.3%CVE-2024-9734HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-47964HIGHHeap-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2EPSS 0.3%CVE-2024-9741HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-7730HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()EPSS 0.3%CVE-2025-22881HIGHHeap-based Buffer Overflow in CNCSoft-G2EPSS 0.3%CVE-2024-9742HIGHTungsten Automation Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2912MEDIUMHDF5 H5Omessage.c H5O_msg_flush heap-based overflowEPSS 0.3%CVE-2025-2923MEDIUMHDF5 H5Fint.c H5F_addr_encode_len heap-based overflowEPSS 0.3%CVE-2025-2914MEDIUMHDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflowEPSS 0.3%CVE-2025-59275HIGHWindows Authentication Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-45679HIGHHeap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a EPSS 0.3%CVE-2026-69242HIGHlibvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident writeEPSS 0.3%