Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2026-11792LOW389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string)EPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2025-62526HIGHOpenWrt ubusd vulnerable to heap buffer overflowEPSS 0.3%CVE-2025-21137HIGHSubstance3D - Designer | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-21139HIGHSubstance3D - Designer | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-32612HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of thEPSS 0.3%CVE-2024-32616HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.EPSS 0.3%CVE-2026-18457HIGHHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.EPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%CVE-2023-4016LOWUnder some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimEPSS 0.3%CVE-2025-55661MEDIUMA heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.3%CVE-2025-6269MEDIUMHDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflowEPSS 0.3%CVE-2025-6270MEDIUMHDF5 H5FSsection.c H5FS__sect_find_node heap-based overflowEPSS 0.3%CVE-2025-55652MEDIUMA heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of EPSS 0.3%CVE-2026-75883MEDIUMPPPD buffer overflow in PEAP response codeEPSS 0.3%CVE-2026-8087MEDIUMOSGeo gdal GDapi.c GDnentries heap-based overflowEPSS 0.3%CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2026-22554HIGHA heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01). A specially crEPSS 0.3%