Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-69578HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-22100HIGHMicroDicom DICOM Heap-based Buffer OverflowEPSS 0.3%CVE-2025-48797HIGHGimp: multiple heap buffer overflows in tga parserEPSS 0.3%CVE-2021-21572HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%CVE-2026-12010HIGHHeap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2025-20720HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2022-45491HIGHBuffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (NovembeEPSS 0.3%CVE-2025-31344HIGHThe giflib open-source component has a buffer overflow vulnerabilityEPSS 0.3%CVE-2025-54244HIGHSubstance3D - Viewer | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-88807HIGHlibXrender RenderQueryPictFormats Reply Heap-based Buffer OverflowEPSS 0.3%CVE-2023-37297HIGHheap memory overflow EPSS 0.3%CVE-2025-21129HIGHSubstance3D - Stager | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-37295HIGHHeap-based Buffer OverflowEPSS 0.3%CVE-2026-8560MEDIUMHeap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bEPSS 0.3%CVE-2025-7033HIGHRockwell Automation Heap-based Buffer Overflow In Arena® SimulationEPSS 0.3%CVE-2025-7025HIGHRockwell Automation Heap-based Buffer Overflow In Arena® SimulationEPSS 0.3%CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2023-37294HIGHHeap-based Buffer OverflowEPSS 0.3%CVE-2024-56827MEDIUMOpenjpeg: heap buffer overflow in lib/openjp2/j2k.cEPSS 0.3%CVE-2025-6499MEDIUMvstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflowEPSS 0.3%