Fallos del tipo CWE-122

3213 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2026-22554HIGHA heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01). A specially crEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2025-58725HIGHWindows COM+ Event System Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-6816MEDIUMHDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflowEPSS 0.3%CVE-2026-18368MEDIUMHeap buffer overflow in ModbusgwdEPSS 0.3%CVE-2026-19156HIGHHeap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2025-7067MEDIUMHDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflowEPSS 0.3%CVE-2022-2948HIGHGE CIMPLICITY Heap-based Buffer OverflowEPSS 0.3%CVE-2024-6154HIGHParallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-7069MEDIUMHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflowEPSS 0.3%CVE-2025-47107HIGHInCopy | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-36702HIGHlibiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.EPSS 0.2%CVE-2026-10194MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflowEPSS 0.2%CVE-2024-7018HIGHHeap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2025-11275MEDIUMOpen Asset Import Library Assimp OpenDDLParserUtils.h getNextSeparator heap-based overflowEPSS 0.2%CVE-2026-18341MEDIUMIBM i is Affected By Buffer Overflow Vulnerability []EPSS 0.2%CVE-2025-6750MEDIUMHDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflowEPSS 0.2%CVE-2024-32620HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the inEPSS 0.2%CVE-2024-32613HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerabEPSS 0.2%