Fallos del tipo CWE-122

3203 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2023-49501HIGHBuffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output funcEPSS 0.4%CVE-2026-18271MEDIUMKenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution VulnerabilityEPSS 0.4%CVE-2026-58471MEDIUMGNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.cEPSS 0.4%CVE-2023-34432HIGHHeap-buffer-overflow in src/formats_i.cEPSS 0.4%CVE-2026-20185HIGHCisco SG350 and SG350X Series Managed Switches SNMP Denial of Service VunerabilityEPSS 0.4%CVE-2026-18302HIGHGIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-54878HIGHHeap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`EPSS 0.4%CVE-2023-1570LOWsyoyo tinydng tiny_dng_loader.h __interceptor_memcpy heap-based overflowEPSS 0.4%CVE-2023-5460LOWDelta Electronics WPLSoft Modbus Data Packet heap-based overflowEPSS 0.4%CVE-2025-5830HIGHAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-93381HIGHBuffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to pEPSS 0.4%CVE-2025-54329HIGHAn issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380EPSS 0.4%CVE-2021-28211—A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.EPSS 0.4%CVE-2026-49921CRITICALIn multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with EPSS 0.4%CVE-2025-51005HIGHA heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the prEPSS 0.4%CVE-2021-34971HIGHFoxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-26967HIGHPJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizerEPSS 0.4%CVE-2024-11509HIGHIrfanView SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-27193HIGHBridge | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-27196HIGHPremiere Pro | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%