Fallos del tipo CWE-122

3211 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-9915HIGHHeap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process toEPSS 0.3%CVE-2026-42046HIGHlibcaca: Heap OOB write in canvas import functions caused by int overflowEPSS 0.3%CVE-2025-59504HIGHAzure Monitor Agent Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-58379HIGHGimp: gimp: heap buffer overflow in read_channel_data()EPSS 0.3%CVE-2025-65406MEDIUMA heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to causeEPSS 0.3%CVE-2026-10989HIGHInappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in speciEPSS 0.3%CVE-2025-11788HIGHHeap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.3%CVE-2024-39380HIGHAfter Effects | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-25390HIGHA heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2025-24453HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-27171HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-27177HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-8443LOWLibopensc: heap buffer overflow in openpgp driver when generating keyEPSS 0.3%CVE-2024-8025HIGHNikon NEF Codec Thumbnail Provider NRW File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-53630HIGHInteger Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in ggufEPSS 0.3%CVE-2025-32401MEDIUMAn Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the EPSS 0.3%CVE-2023-4682MEDIUMHeap-based Buffer Overflow in gpac/gpacEPSS 0.3%CVE-2018-8834—Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prEPSS 0.3%CVE-2025-59191HIGHWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-47311HIGHHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258EPSS 0.3%