Weaknesses of type CWE-122

3,210 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-21494MEDIUMiccDEV has heap buffer overflow in CIccTagLut8::Validate()EPSS 0.2%CVE-2026-70653MEDIUMlibvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance imageEPSS 0.2%CVE-2026-21358MEDIUMInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-0033HIGHIn multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalationEPSS 0.2%CVE-2026-20462MEDIUMIn Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2025-11010MEDIUMvstakhov libucl ucl_util.c ucl_include_common heap-based overflowEPSS 0.2%CVE-2025-48910MEDIUMBuffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-46643LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 0.2%CVE-2025-55664MEDIUMA heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of SeEPSS 0.2%CVE-2026-44983HIGHsmallbitvec: Safe API Triggered Heap Buffer Overflow via Integer OverflowEPSS 0.2%CVE-2026-24180HIGHNVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of thisEPSS 0.2%CVE-2026-53465MEDIUMImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageEPSS 0.2%CVE-2026-28686MEDIUMImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output bufferEPSS 0.2%CVE-2026-86142MEDIUMIn libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.EPSS 0.2%CVE-2023-30763HIGHHeap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation EPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-39103MEDIUMBuffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of servicEPSS 0.2%CVE-2025-1252MEDIUMHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-91767MEDIUMHeap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CNEPSS 0.2%CVE-2026-40528LOWOpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.cEPSS 0.2%