Fallos del tipo CWE-122

3212 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-50375MEDIUMDirectX Graphics Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-21169HIGHSubstance3D - Designer | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-27286MEDIUMInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-27301MEDIUMAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-57807LOWImageMagick BlobStream Forward-Seek Under-AllocationEPSS 0.3%CVE-2024-13050HIGHAshlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-13051HIGHAshlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-7543HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-32318HIGHIn Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no adEPSS 0.3%CVE-2026-15169MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2026-11822HIGHSQLite before 3.53.2 Memory Corruption in FTS5 ExtensionEPSS 0.3%CVE-2024-7544HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2024-7545HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-49732HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-61837HIGHFormat Plugins | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-49742HIGHWindows Graphics Component Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-88370MEDIUMlibconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bEPSS 0.3%CVE-2025-15277HIGHFontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-15279HIGHFontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-36763HIGHHeap Buffer Overflow in Tcg2MeasureGptTableEPSS 0.3%