Fallos del tipo CWE-122

3209 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2023-3463MEDIUMGE Digital CIMPLICITY Heap-based Buffer OverflowEPSS 0.4%CVE-2026-24283HIGHMultiple UNC Provider Kernel Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-76886HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.4%CVE-2023-47056HIGHZDI-CAN-21763: Adobe Premiere Pro MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-3082HIGHGStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2025-5750HIGHWOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-21337MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-39492HIGHPDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-47051MEDIUMZDI-CAN-21683: Adobe Audition MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-22058HIGHA buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated EPSS 0.4%CVE-2026-6361HIGHHeap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage EPSS 0.4%CVE-2024-39392HIGHAdobe Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-61390HIGHThere is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunctiEPSS 0.4%CVE-2024-52996HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-48805HIGHMicrosoft MPEG-2 Video Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-52995HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-1275HIGHJPG File Parsing Heap-Based Overflow VulnerabilityEPSS 0.4%CVE-2025-5477HIGHSony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-5479HIGHSony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%