Fallos del tipo CWE-122

3212 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-2923MEDIUMHDF5 H5Fint.c H5F_addr_encode_len heap-based overflowEPSS 0.3%CVE-2024-9742HIGHTungsten Automation Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2914MEDIUMHDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflowEPSS 0.3%CVE-2025-2912MEDIUMHDF5 H5Omessage.c H5O_msg_flush heap-based overflowEPSS 0.3%CVE-2026-21277HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-2019HIGHAshlar-Vellum Cobalt VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-51795HIGHBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showEPSS 0.3%CVE-2026-21304HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-10502HIGHHeap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.3%CVE-2025-2900HIGHIBM Semeru Runtime denial of serviceEPSS 0.3%CVE-2025-1656HIGHPDF File Parsing Heap-based Overflow VulnerabilityEPSS 0.3%CVE-2026-68897HIGHMicrosoft Standard XPS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-10744HIGHIBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validationEPSS 0.3%CVE-2024-1848HIGHMultiple vulnerabilities exist in file reading procedure in SOLIDWORKS Desktop on Release SOLIDWORKS 2024EPSS 0.3%CVE-2025-7545MEDIUMGNU Binutils objcopy.c copy_section heap-based overflowEPSS 0.3%CVE-2026-27285MEDIUMInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-53310MEDIUMA Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 wheEPSS 0.3%CVE-2024-32229HIGHFFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.EPSS 0.3%CVE-2025-47134HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-11933HIGHFuji Electric Monitouch V-SFT X1 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%