Fallos del tipo CWE-122

3214 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-28686MEDIUMImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output bufferEPSS 0.2%CVE-2026-53465MEDIUMImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame imageEPSS 0.2%CVE-2023-30763HIGHHeap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation EPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-39103MEDIUMBuffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of servicEPSS 0.2%CVE-2025-1252MEDIUMHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-91767MEDIUMHeap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CNEPSS 0.2%CVE-2026-40528LOWOpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.cEPSS 0.2%CVE-2026-54001HIGHosquery: Heap buffer overflow via `authenticode` table (Windows)EPSS 0.2%CVE-2026-49429HIGHKernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctlEPSS 0.2%CVE-2026-54000HIGHosquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)EPSS 0.2%CVE-2026-30931MEDIUMImageMagick has a heap-based buffer overflow in UHDR encoderEPSS 0.2%CVE-2026-81474HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attaEPSS 0.2%CVE-2026-49430HIGHKernel heap overflow in ZFS_IOC_RECV_NEW ioctlEPSS 0.2%CVE-2026-23750HIGHGolioth Pouch (prior to commit 1b2219a1) BLE GATT Heap-based Buffer OverflowEPSS 0.2%CVE-2026-35590MEDIUMPossible out-of-bounds read leading to crash when decoding well-crafted EXIF metadataEPSS 0.2%CVE-2025-46373HIGHA Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.EPSS 0.2%CVE-2025-8300HIGHRealtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-18938MEDIUMP11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systemsEPSS 0.2%CVE-2025-8302HIGHRealtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.2%