Weaknesses of type CWE-122

3,209 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-68514MEDIUMOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep imagesEPSS 0.2%CVE-2026-61714HIGHFluidSynth: Heap Buffer Overflow in MIDI PlayerEPSS 0.2%CVE-2026-12030HIGHOut of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2025-54496HIGHFuji Electric Monitouch V-SFT-6 Heap-based Buffer OverflowEPSS 0.2%CVE-2026-0130MEDIUMIn RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information dEPSS 0.2%CVE-2026-27799MEDIUMImageMagick has a heap Buffer Over-read in its DJVU image format handlerEPSS 0.2%CVE-2026-42309MEDIUMPillow: Heap buffer overflow with nested list coordinatesEPSS 0.2%CVE-2025-1218LOWVarious packet overreads in mysqlnd_writeprotocol.cEPSS 0.2%CVE-2025-6490MEDIUMsparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflowEPSS 0.2%CVE-2026-27940HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 FixEPSS 0.2%CVE-2025-46333HIGHz2d OOB composition could lead to invalid memory access and corruptionEPSS 0.2%CVE-2025-11947LOWbftpd Configuration File options.c expand_groups heap-based overflowEPSS 0.2%CVE-2025-6494MEDIUMsparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflowEPSS 0.2%CVE-2026-90577MEDIUMGPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflowEPSS 0.2%CVE-2026-68765MEDIUMhashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token FieldEPSS 0.2%CVE-2026-46655HIGHvirtio-win: Integer overflow causing a heap overflow in Viosock driverEPSS 0.2%CVE-2025-48990HIGHNeKernel has Heap Overflow in `rt_copy_memory`EPSS 0.2%CVE-2026-35591HIGHPossible heap-based buffer overflow when decoding TIFF image containing well-crafted tileEPSS 0.2%CVE-2025-64031LOWlibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressEPSS 0.2%CVE-2026-45761LOWSuricata detect: case-insensitive frame handling can cause heap buffer overflow during rule loadEPSS 0.2%