Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2022-38414HIGHAdobe InDesign SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-20777HIGHA heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master EPSS 0.5%CVE-2025-54907HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-34488HIGHNanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.EPSS 0.5%CVE-2025-49697HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-18585MEDIUMGL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflowEPSS 0.5%CVE-2026-34502HIGHApache Portable Runtime Utility: Heap buffer overflow in APR memcached clientEPSS 0.5%CVE-2023-50246MEDIUMjq has heap-buffer-overflow vulnerability in the function decToString in decNumber.cEPSS 0.5%CVE-2026-24679HIGHFreeRDP has a heap-buffer-overflow in urb_select_interfaceEPSS 0.5%CVE-2025-2756MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflowEPSS 0.5%CVE-2026-34501HIGHApache Portable Runtime Utility: Heap buffer overflow in APR redis clientEPSS 0.5%CVE-2026-10849HIGHHeap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bodyEPSS 0.5%CVE-2025-62470HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-65079MEDIUMHeap-based buffer overflow vulnerability in Postscript interpreterEPSS 0.5%CVE-2026-87527CRITICALBuffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%CVE-2026-78948CRITICALBuffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%CVE-2026-79130CRITICALBuffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%CVE-2026-87654CRITICALBuffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside tEPSS 0.5%CVE-2026-76036CRITICALBuffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside tEPSS 0.5%CVE-2026-0821MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_constructor heap-based overflowEPSS 0.5%