Weaknesses of type CWE-122

3,195 results

Transbordamento de heap (heap overflow)

Ocorre quando um programa escreve dados além dos limites de um buffer alocado dinamicamente na memória heap, sobrescrevendo dados adjacentes ou metadados do alocador. Isso permite que um atacante corrompa estruturas críticas, execute código arbitrário ou cause travamento da aplicação.

Example

Uma função recebe um tamanho de entrada sem validar e copia para um buffer: `strcpy(heap_buffer, user_input)` sem verificar se user_input cabe. Se o usuário enviar 1000 bytes para um buffer de 256, o overflow sobrescreve estruturas próximas no heap e pode ser explorado para RCE.

How to mitigate

Use funções seguras de cópia (`strncpy`, `strlcpy`), valide e limite o tamanho da entrada antes de copiar, e considere usar linguagens com gerenciamento automático de memória ou ferramentas como AddressSanitizer durante testes para detectar overflows.

CVE-2021-31429HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker muEPSS 0.4%CVE-2026-66039HIGHFFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF FileEPSS 0.4%CVE-2025-44904HIGHhdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.EPSS 0.4%CVE-2023-28262HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-46488CRITICALsqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cEPSS 0.4%CVE-2026-62699MEDIUMWindows Universal Disk Format File System Driver (UDFS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-71349MEDIUMWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-50009HIGHFFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 comEPSS 0.4%CVE-2026-71348MEDIUMWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-50299MEDIUMWindows Storage Spaces Direct Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-40929MEDIUMCpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impactEPSS 0.4%CVE-2026-68833MEDIUMWindows NTFS Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-50492MEDIUMWindows Resilient File System (ReFS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-69566MEDIUMWindows NTFS Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-71350MEDIUMWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-72985MEDIUMVolume Shadow Copy Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-50668MEDIUMWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-45993MEDIUMGiflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.EPSS 0.4%CVE-2023-38076HIGHA vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), TeamcenEPSS 0.4%CVE-2026-54132MEDIUMWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.4%