Fallos del tipo CWE-122

3213 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2024-29163HIGHHDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denEPSS 0.2%CVE-2026-25583HIGHiccDEV vulnerable to Heap Buffer Overflow in CIccFileIO::Read8()EPSS 0.2%CVE-2024-29160HIGHHDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer EPSS 0.2%CVE-2024-8591HIGHAutodesk AutoCAD 3DM File Parsing Heap-based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2026-14759MEDIUMradareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflowEPSS 0.2%CVE-2026-18298HIGHGStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-5447MEDIUMHeap buffer overflow in CertFromX509() via AuthorityKeyIdentifierEPSS 0.2%CVE-2026-18102LOWIBM i Buffer OverflowEPSS 0.2%CVE-2026-21281HIGHInCopy | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-41981HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2021-26330—AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.EPSS 0.2%CVE-2025-61154MEDIUMHeap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of ServiEPSS 0.2%CVE-2025-3791MEDIUMsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflowEPSS 0.2%CVE-2023-43688HIGHAn issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encEPSS 0.2%CVE-2025-70303MEDIUMA heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 filEPSS 0.2%CVE-2023-24551HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-24550HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2025-11206HIGHHeap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.2%CVE-2025-70302MEDIUMA heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted EPSS 0.2%CVE-2026-21491MEDIUMiccDEV has unicode buffer overflow in CIccTagTextDescriptionEPSS 0.2%