Fallos del tipo CWE-122

3211 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-10929HIGHHeap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer EPSS 0.3%CVE-2025-61824HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-48071HIGHOpenEXR's Forged Unpacked Size can Lead to Heap-Based Buffer Overflow in Deep Scanline ParsingEPSS 0.3%CVE-2025-54209HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-21406HIGHHeap-based buffer overflow in Axis A1001 Network Door Controller's OSDP communicationEPSS 0.3%CVE-2024-43790MEDIUMheap-buffer-overflow in do_search() in Vim < 9.1.0689EPSS 0.3%CVE-2026-38821HIGHA heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal netEPSS 0.3%CVE-2026-20465HIGHIn wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escaEPSS 0.3%CVE-2024-1062MEDIUM389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)EPSS 0.3%CVE-2026-7353HIGHHeap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to EPSS 0.3%CVE-2023-37342HIGHKofax Power PDF PNG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-2474HIGHCrypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom()EPSS 0.3%CVE-2026-8525HIGHHeap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2026-4892HIGHCVE-2026-4892EPSS 0.3%CVE-2020-1906—A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-oEPSS 0.3%CVE-2025-1788MEDIUMrizinorg rizin utf8.c rz_utf8_encode heap-based overflowEPSS 0.3%CVE-2026-7900HIGHHeap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to EPSS 0.3%CVE-2023-29125CRITICALHeap overflow in CM_main.exe binary in Enel X JuiceBoxEPSS 0.3%CVE-2024-12669HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2023-37335HIGHKofax Power PDF BMP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%