Fallos del tipo CWE-122

3202 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-57106HIGHKitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BEPSS 0.4%CVE-2026-5275HIGHHeap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafEPSS 0.4%CVE-2023-32157MEDIUMTesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2026-5272HIGHHeap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML EPSS 0.4%CVE-2023-28905HIGHHeap buffer overflow in picserverEPSS 0.4%CVE-2026-21676HIGHiccDEV has a Heap-based Buffer Overflow in its CIccMBB::Validate() functionEPSS 0.4%CVE-2024-47417HIGHAnimate | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-2310MEDIUMHDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflowEPSS 0.4%CVE-2023-42038HIGHKofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-73242HIGHFreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`EPSS 0.4%CVE-2025-32396HIGHAn Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the librEPSS 0.4%CVE-2023-34289HIGHAshlar-Vellum Cobalt Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-34299HIGHAshlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-32400HIGHAn Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the librEPSS 0.4%CVE-2025-32397HIGHAn Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the librEPSS 0.4%CVE-2023-35709HIGHAshlar-Vellum Cobalt Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38090HIGHKofax Power PDF popUpMenu Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-3291MEDIUMHeap-based Buffer Overflow in gpac/gpacEPSS 0.4%CVE-2024-43756HIGHPhotoshop Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-57638HIGHBuffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.EPSS 0.4%