Weaknesses of type CWE-122

3,202 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-39113MEDIUMBuffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f10695EPSS 0.2%CVE-2026-28420MEDIUMVim has Heap-based Buffer Overflow and OOB Read in :terminalEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2026-40310MEDIUMImageMagick: Heap out-of-bounds write in JP2 encoderEPSS 0.2%CVE-2026-2467CRITICALHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2025-11464HIGHAshlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-5403HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-5405HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2024-22453HIGHDell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit tEPSS 0.2%CVE-2026-25205HIGHHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash EPSS 0.2%CVE-2026-25576MEDIUMImageMagick: Out of bounds read in multiple coders read raw pixel dataEPSS 0.2%CVE-2026-55893HIGHCapstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecodeEPSS 0.2%CVE-2026-75649HIGHBridge | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2026-56392LOWHeap-based Buffer Overflow in GNU coreutilsEPSS 0.2%CVE-2024-6031HIGHTesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2026-63422HIGHOpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds writeEPSS 0.2%CVE-2026-8484MEDIUMHeap buffer overflow in JansiEPSS 0.2%CVE-2026-15520MEDIUMGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2026-8997MEDIUMHeap Buffer Overflow in vifmEPSS 0.2%CVE-2026-15182MEDIUMGNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflowEPSS 0.2%