Fallos del tipo CWE-122

3210 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-3915HIGHHeap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via EPSS 0.4%CVE-2023-34474—A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could triEPSS 0.4%CVE-2026-4673HIGHHeap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory writeEPSS 0.4%CVE-2023-2241MEDIUMPoDoFo PdfXRefStreamParserObject.cpp readXRefStreamEntry heap-based overflowEPSS 0.4%CVE-2023-38212HIGHZDI-CAN-21093: Adobe Dimension GLB File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-3555HIGHPhilips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-2650HIGHHeap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.4%CVE-2025-66862HIGHA buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service vEPSS 0.4%CVE-2024-38796MEDIUMInteger overflow in PeCoffLoaderRelocateImageEPSS 0.4%CVE-2023-1010MEDIUMvox2png vox2png.c heap-based overflowEPSS 0.4%CVE-2025-64330HIGHSuricata is vulnerable to a heap buffer overflow on verdictEPSS 0.4%CVE-2026-34150HIGHWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingEPSS 0.4%CVE-2026-33298HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor ParsingEPSS 0.4%CVE-2026-81389HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-55118HIGHBMC Control-M/Agent memory corruption in SSL/TLS communicationEPSS 0.4%CVE-2026-24822CRITICALa heap-based buffer overflow vulnerability in ttttupup/wxhelper via src/mongoose.EPSS 0.4%CVE-2026-2920HIGHGStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-59938MEDIUMHeap buffer overflow in wazuh-analysisdEPSS 0.4%CVE-2026-26073MEDIUMEVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queueEPSS 0.4%CVE-2026-48994MEDIUMImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systemsEPSS 0.4%