Fallos del tipo CWE-122

3213 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-34534MEDIUMiccDEV: HBO in CIccMpeSpectralMatrix::Describe()EPSS 0.2%CVE-2024-27372MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-4657HIGHA buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, LenEPSS 0.2%CVE-2026-58306MEDIUMHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525EPSS 0.2%CVE-2026-18370MEDIUMHeap-based buffer overflow in entrEPSS 0.2%CVE-2025-8351HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed fileEPSS 0.2%CVE-2026-21358MEDIUMInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-5043HIGH3DM File Parsing Heap-Based Overflow VulnerabilityEPSS 0.2%CVE-2026-91088LOWGPAC URL url.c gf_url_concatenate_ex heap-based overflowEPSS 0.2%CVE-2024-0033HIGHIn multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalationEPSS 0.2%CVE-2026-70653MEDIUMlibvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance imageEPSS 0.2%CVE-2026-21494MEDIUMiccDEV has heap buffer overflow in CIccTagLut8::Validate()EPSS 0.2%CVE-2026-20462MEDIUMIn Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malEPSS 0.2%CVE-2025-11010MEDIUMvstakhov libucl ucl_util.c ucl_include_common heap-based overflowEPSS 0.2%CVE-2025-48910MEDIUMBuffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-46643LOWDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 0.2%CVE-2025-55664MEDIUMA heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of SeEPSS 0.2%CVE-2026-44983HIGHsmallbitvec: Safe API Triggered Heap Buffer Overflow via Integer OverflowEPSS 0.2%CVE-2026-24180HIGHNVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of thisEPSS 0.2%CVE-2026-53465MEDIUMImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageEPSS 0.2%