Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-58725HIGHWindows COM+ Event System Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-18368MEDIUMHeap buffer overflow in ModbusgwdEPSS 0.3%CVE-2026-19156HIGHHeap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2025-7067MEDIUMHDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflowEPSS 0.3%CVE-2025-7069MEDIUMHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflowEPSS 0.3%CVE-2022-2948HIGHGE CIMPLICITY Heap-based Buffer OverflowEPSS 0.3%CVE-2024-6154HIGHParallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-47107HIGHInCopy | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-36702HIGHlibiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.EPSS 0.2%CVE-2026-10194MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflowEPSS 0.2%CVE-2024-7018HIGHHeap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2025-11275MEDIUMOpen Asset Import Library Assimp OpenDDLParserUtils.h getNextSeparator heap-based overflowEPSS 0.2%CVE-2025-6750MEDIUMHDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflowEPSS 0.2%CVE-2026-18341MEDIUMIBM i is Affected By Buffer Overflow Vulnerability []EPSS 0.2%CVE-2024-32613HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerabEPSS 0.2%CVE-2025-23308LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by gettiEPSS 0.2%CVE-2026-8552MEDIUMHeap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memoryEPSS 0.2%CVE-2024-32620HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the inEPSS 0.2%CVE-2026-72927MEDIUMWinsock Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-43582HIGHSubstance3D - Viewer | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%