Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2026-13587MEDIUMseladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflowEPSS 0.7%CVE-2025-14425HIGHGIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-23378HIGHPrint 3D Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-62458HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2023-23390HIGH3D Builder Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-31806CRITICALFreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap DimensionsEPSS 0.7%CVE-2024-56732CRITICALHarfBuzz heap-buffer-overflow on hb_cairo_glyphs_from_bufferEPSS 0.7%CVE-2026-5402HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.7%CVE-2025-47169HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-57637HIGHBuffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowingEPSS 0.7%CVE-2023-49600HIGHAn out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can EPSS 0.7%CVE-2023-23377HIGH3D Builder Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-26061HIGHA heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file canEPSS 0.6%CVE-2025-40907MEDIUMFCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) libraryEPSS 0.6%CVE-2025-21375HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2021-3903HIGHHeap-based Buffer Overflow in vim/vimEPSS 0.6%CVE-2026-64830HIGHFFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle DemuxerEPSS 0.6%CVE-2026-25646HIGHLIBPNG has a heap buffer overflow in png_set_quantizeEPSS 0.6%CVE-2023-27911HIGHA user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or EPSS 0.6%CVE-2022-38404HIGHAdobe InCopy SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%