Fallos del tipo CWE-122

3212 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-10881HIGHCATPRODUCT File Parsing Heap-Based Overflow VulnerabilityEPSS 0.3%CVE-2025-24443HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-16118HIGHXdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.cEPSS 0.3%CVE-2025-20742HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2026-10575HIGHIBM MQ queue manager is vulnerable to remote code executionEPSS 0.3%CVE-2026-69878MEDIUMWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-54211HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-73017HIGHGraphics Kernel Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-30299HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-34318HIGHHeap-buffer-overflow in src/hcom.cEPSS 0.3%CVE-2024-9734HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9741HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-47964HIGHHeap-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2EPSS 0.3%CVE-2023-41140—A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicEPSS 0.3%CVE-2025-22881HIGHHeap-based Buffer Overflow in CNCSoft-G2EPSS 0.3%CVE-2024-7730HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()EPSS 0.3%CVE-2024-9743HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-69242HIGHlibvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident writeEPSS 0.3%CVE-2025-2923MEDIUMHDF5 H5Fint.c H5F_addr_encode_len heap-based overflowEPSS 0.3%CVE-2024-9742HIGHTungsten Automation Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%