Weaknesses of type CWE-122

3,210 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2024-10253MEDIUMA potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to causeEPSS 0.1%CVE-2021-25475LOWA possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and cEPSS 0.1%CVE-2024-0018HIGHIn convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could leadEPSS 0.1%CVE-2026-15164MEDIUMHeap-based Buffer Overflow in ciscodumpEPSS 0.1%CVE-2025-11961LOWOOBR and OOBW in pcap_ether_aton() in libpcapEPSS 0.1%CVE-2022-44427MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-18495MEDIUMLibtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthroughEPSS 0.1%CVE-2025-20731MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-15449MEDIUMTOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruptionEPSS 0.1%CVE-2025-20734MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-0059HIGHIn multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead EPSS 0.1%CVE-2026-21399MEDIUMHeap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0EPSS 0.1%CVE-2026-28546MEDIUMBuffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2024-49714HIGHIn avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device eEPSS 0.1%CVE-2026-62381MEDIUMluci-lib-px5g 2040-bit Certificate Signing Heap Buffer OverflowEPSS 0.1%CVE-2025-62624HIGHA heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially EPSS 0.1%CVE-2022-36858MEDIUMA heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior toEPSS 0.1%CVE-2022-36842MEDIUMA heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-202EPSS 0.1%CVE-2022-36863MEDIUMA heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SEPSS 0.1%CVE-2022-36841MEDIUMA heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR SeEPSS 0.1%