Fallos del tipo CWE-122

3214 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-76883MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-86926HIGHA heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 dataEPSS 0.1%CVE-2026-76889MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-20502HIGHIn vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no addEPSS 0.1%CVE-2026-95393MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2026-10230MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflowEPSS 0.1%CVE-2024-10254MEDIUMA potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attackerEPSS 0.1%CVE-2025-36923HIGHIn NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. ThEPSS 0.1%CVE-2026-73072HIGHVim: Heap Buffer Overflow when Loading a Spell FileEPSS 0.1%CVE-2026-10229MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.1%CVE-2026-7310MEDIUMA heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local acceEPSS 0.1%CVE-2026-46692MEDIUMImageMagick: Heap Buffer Over-Write in distributed pixel cache serverEPSS 0.1%CVE-2024-10253MEDIUMA potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to causeEPSS 0.1%CVE-2026-10231MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflowEPSS 0.1%CVE-2026-10200MEDIUMAssimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflowEPSS 0.1%CVE-2025-20729MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2021-25475LOWA possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and cEPSS 0.1%CVE-2026-15164MEDIUMHeap-based Buffer Overflow in ciscodumpEPSS 0.1%CVE-2024-0018HIGHIn convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could leadEPSS 0.1%CVE-2022-44427MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%