Fallos del tipo CWE-122

3214 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2025-8301HIGHRealtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-8299HIGHRealtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-96417MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-63451LOWSuricata detect: frame rules without content and with transform can cause heap buffer overflow during rule loadEPSS 0.1%CVE-2026-30936MEDIUMImageMagick has a heap Buffer Overflow in WaveletDenoiseImageEPSS 0.1%CVE-2026-21488MEDIUMiccDEV has Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null TerminationEPSS 0.1%CVE-2026-54896LOWOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large IndentEPSS 0.1%CVE-2025-20741MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-33987HIGHFreeRDP: Persistent Cache bmpSize Desync - Heap OOB WriteEPSS 0.1%CVE-2024-46993MEDIUMElectron Vulnerable to Heap Buffer Overflow in NativeImage::CreateFromPathEPSS 0.1%CVE-2026-20480MEDIUMIn Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User exEPSS 0.1%CVE-2022-39852HIGHA heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker toEPSS 0.1%CVE-2022-26092HIGHImproper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.EPSS 0.1%CVE-2026-70654MEDIUMlibvips: A well-crafted PPM image processed via a custom source could lead to possible heap buffer write overflowEPSS 0.1%CVE-2026-30937MEDIUMImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculationEPSS 0.1%CVE-2026-56135HIGHIn NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows EPSS 0.1%CVE-2026-12193HIGHVS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflowEPSS 0.1%CVE-2026-15165MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-6530MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-92368HIGHHeap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code ExecutionEPSS 0.1%