Fallos del tipo CWE-122

3213 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-6494MEDIUMsparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflowEPSS 0.2%CVE-2025-11947LOWbftpd Configuration File options.c expand_groups heap-based overflowEPSS 0.2%CVE-2026-27940HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 FixEPSS 0.2%CVE-2026-3407MEDIUMYosysHQ yosys BLIF File rtlil.h set heap-based overflowEPSS 0.2%CVE-2025-48990HIGHNeKernel has Heap Overflow in `rt_copy_memory`EPSS 0.2%CVE-2026-68765MEDIUMhashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token FieldEPSS 0.2%CVE-2026-46655HIGHvirtio-win: Integer overflow causing a heap overflow in Viosock driverEPSS 0.2%CVE-2026-90577MEDIUMGPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflowEPSS 0.2%CVE-2026-35591HIGHPossible heap-based buffer overflow when decoding TIFF image containing well-crafted tileEPSS 0.2%CVE-2026-45761LOWSuricata detect: case-insensitive frame handling can cause heap buffer overflow during rule loadEPSS 0.2%CVE-2025-64031LOWlibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressEPSS 0.2%CVE-2023-0208HIGH NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow throughEPSS 0.2%CVE-2026-53720MEDIUMpymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too smallEPSS 0.2%CVE-2026-76887LOWHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-11824HIGHSQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterateEPSS 0.2%CVE-2026-11143MEDIUMOut of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maliEPSS 0.2%CVE-2026-34535MEDIUMiccDEV: SEGV in CIccTagArray::Cleanup()EPSS 0.2%CVE-2023-32461MEDIUM Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potEPSS 0.2%CVE-2026-52834HIGHjxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platformsEPSS 0.2%CVE-2026-79591HIGHA heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation oEPSS 0.2%