Weaknesses of type CWE-122

3,202 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-12495HIGHAcademy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-68513HIGHOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collisionEPSS 0.2%CVE-2026-15170MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2023-31031MEDIUMCVEEPSS 0.2%CVE-2025-12839HIGHAcademy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-5915MEDIUMLibarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.cEPSS 0.2%CVE-2023-23782HIGHA heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versiEPSS 0.2%CVE-2026-61721HIGHFluidSynth: Heap-based buffer overrun for DLS samplesEPSS 0.2%CVE-2026-30979HIGHiccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp()EPSS 0.2%CVE-2025-9457HIGHPRT File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-13976MEDIUMInsufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pEPSS 0.2%CVE-2025-53184MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53180MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53182MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53183MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2026-68515HIGHOpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel unionEPSS 0.2%CVE-2022-34454MEDIUMDell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploEPSS 0.2%CVE-2026-39113MEDIUMBuffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f10695EPSS 0.2%CVE-2026-9541MEDIUMSquirrel Cnut File sqobject.cpp ReadObject heap-based overflowEPSS 0.2%CVE-2025-53179MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%