Fallos del tipo CWE-122

3209 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-67549HIGHOpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds writeEPSS 0.4%CVE-2025-6516MEDIUMHDF5 H5Fint.c H5F_addr_decode_len heap-based overflowEPSS 0.4%CVE-2026-28618HIGHIn dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no EPSS 0.4%CVE-2026-49882HIGHIn rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote codeEPSS 0.4%CVE-2024-29508LOWArtifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_EPSS 0.4%CVE-2025-1051HIGHSonos Era 300 Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-49727HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-23155HIGHMultiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based productsEPSS 0.4%CVE-2025-22134MEDIUMheap-buffer-overflow with visual mode in Vim < 9.1.1003EPSS 0.4%CVE-2025-64680HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-41437MEDIUMA heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DEPSS 0.4%CVE-2026-10946HIGHHeap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UEPSS 0.4%CVE-2026-3913HIGHHeap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.4%CVE-2026-4675HIGHHeap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read viaEPSS 0.4%CVE-2026-13798CRITICALHeap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.4%CVE-2026-4673HIGHHeap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory writeEPSS 0.4%CVE-2026-10858CRITICALIBM MQ for HPE NonStop is vulnerable to a denial of service attackEPSS 0.4%CVE-2026-17680CRITICALHeap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendererEPSS 0.4%CVE-2026-17951HIGHHeap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read viaEPSS 0.4%CVE-2026-6296CRITICALHeap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape viaEPSS 0.4%