Fallos del tipo CWE-122

3213 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2024-32618HIGHHDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of theEPSS 0.2%CVE-2024-34408MEDIUMTencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (PEPSS 0.2%CVE-2026-21357HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-11495MEDIUMGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowEPSS 0.2%CVE-2026-22027MEDIUMCryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring ConversionEPSS 0.2%CVE-2025-22880HIGHHeap-based Buffer Overflow in CNCSoft-G2EPSS 0.2%CVE-2026-29022MEDIUMmackron / dr_libs dr_wav.h Heap Buffer Overflow via WAV FileEPSS 0.2%CVE-2024-21913HIGHRockwell Automation Arena Simulation Vulnerable To Memory CorruptionEPSS 0.2%CVE-2022-37864—A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past EPSS 0.2%CVE-2026-53938HIGHOpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)EPSS 0.2%CVE-2025-2531HIGHLuxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-6992MEDIUMMemory corruption issues is Cloudflare zlib implementationEPSS 0.2%CVE-2025-67873MEDIUMCapstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflowEPSS 0.2%CVE-2025-49560HIGHSubstance3D - Viewer | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-61838HIGHFormat Plugins | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2026-11124HIGHInteger overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.2%CVE-2024-29165HIGHHDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causingEPSS 0.2%CVE-2023-28527MEDIUMIBM Informix Dynamic Server buffer overflowEPSS 0.2%CVE-2025-54630MEDIUM:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect EPSS 0.2%CVE-2023-28526MEDIUMIBM Informix Dynamic Server buffer overflowEPSS 0.2%