Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2025-4096HIGHHeap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a EPSS 0.5%CVE-2023-47118HIGHHeap buffer overflow in T64 codec decompressionEPSS 0.5%CVE-2024-46264HIGHcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.EPSS 0.5%CVE-2024-20522MEDIUMCisco Small Business RV042, RV042G, RV320, and RV325 Denial of Service VulnerabilitiesEPSS 0.5%CVE-2024-40754MEDIUMHeap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects EscargEPSS 0.5%CVE-2025-53723HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-53155HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-44428HIGHMuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-26284MEDIUMImageMagick has heap overflow in pcd decoder that leads to out of bounds read.EPSS 0.5%CVE-2026-40691HIGHPacket of death for DNSCrypt over TCPEPSS 0.5%CVE-2025-14673MEDIUMgmg137 snap7-rs client.rs as_ct_write heap-based overflowEPSS 0.5%CVE-2026-75893HIGHHeap based buffer overflow at ipaccess_proxy_read_msg()EPSS 0.5%CVE-2026-33633HIGHKitty has a Heap Buffer Overflow in its Graphics Protocol HandlerEPSS 0.5%CVE-2026-67860HIGHopen62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memEPSS 0.5%CVE-2026-38347HIGHA heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to causEPSS 0.5%CVE-2026-33986HIGHFreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB WriteEPSS 0.5%CVE-2026-77102HIGHCommServe Denial of ServiceEPSS 0.5%CVE-2025-14672MEDIUMgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflowEPSS 0.5%CVE-2026-18282HIGHSony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-18281HIGHSony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%