Weaknesses of type CWE-122

3,210 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-1652MEDIUMA potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local autheEPSS 0.1%CVE-2026-15174MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2024-27209HIGHthere is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional eEPSS 0.1%CVE-2026-24922MEDIUMBuffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-42783MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-3229LOWInteger Overflow in Certificate Chain AllocationEPSS 0.1%CVE-2025-36907HIGHIn draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could leEPSS 0.1%CVE-2026-24925HIGHHeap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-44430MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-36906HIGHIn ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lEPSS 0.1%CVE-2022-44429MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-44428MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-36902MEDIUMIn syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead EPSS 0.1%CVE-2025-20774MEDIUMIn display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malEPSS 0.1%CVE-2026-0100HIGHIn Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of priEPSS 0.1%CVE-2026-95387HIGHHeap-based Buffer Overflow in WiresharkEPSS —CVE-2026-96416MEDIUMHeap-based Buffer Overflow in WiresharkEPSS —CVE-2026-95393MEDIUMHeap-based Buffer Overflow in WiresharkEPSS —CVE-2026-95284—Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside tEPSS —CVE-2026-96423MEDIUMHeap-based Buffer Overflow in WiresharkEPSS —