Weaknesses of type CWE-122

3,202 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2024-41981HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2021-26330—AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.EPSS 0.2%CVE-2026-3463MEDIUMxlnt-community xlnt Compound Document binary.hpp append heap-based overflowEPSS 0.2%CVE-2025-61154MEDIUMHeap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of ServiEPSS 0.2%CVE-2025-3791MEDIUMsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflowEPSS 0.2%CVE-2025-70302MEDIUMA heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted EPSS 0.2%CVE-2023-24551HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-43688HIGHAn issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encEPSS 0.2%CVE-2023-24550HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2025-70303MEDIUMA heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 filEPSS 0.2%CVE-2025-11206HIGHHeap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.2%CVE-2025-15537MEDIUMMapnik dbfile.cpp string_value heap-based overflowEPSS 0.2%CVE-2026-21491MEDIUMiccDEV has unicode buffer overflow in CIccTagTextDescriptionEPSS 0.2%CVE-2026-21490MEDIUMiccDEV has heap buffer overflow in CIccTagLut16::Validate()EPSS 0.2%CVE-2025-50130HIGHA heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC CO., LTD. Opening VEPSS 0.2%CVE-2025-14956MEDIUMWebAssembly Binaryen wasm-binary.cpp readExport heap-based overflowEPSS 0.2%CVE-2026-21504MEDIUMHeap Buffer Overflow in iccDEV ToneMap ParserEPSS 0.2%CVE-2023-40465HIGHImproper input leads to DoSEPSS 0.2%CVE-2025-31164MEDIUMfig2dev heap-buffer overflowEPSS 0.2%CVE-2025-1273HIGHPDF File Parsing Heap-Based Overflow VulnerabilityEPSS 0.2%