Fallos del tipo CWE-122

3214 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2022-36841MEDIUMA heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR SeEPSS 0.1%CVE-2022-36842MEDIUMA heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-202EPSS 0.1%CVE-2026-88386MEDIUMlibsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV fiEPSS 0.1%CVE-2025-32325HIGHIn appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of pEPSS 0.1%CVE-2026-41981MEDIUMOut-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-21104HIGHHeap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary codeEPSS 0.1%CVE-2026-23788MEDIUMAn issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due toEPSS 0.1%CVE-2025-26455HIGHIn multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%CVE-2026-49932HIGHIn parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation oEPSS 0.1%CVE-2026-58820HIGHIn multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege witEPSS 0.1%CVE-2026-55323HIGHIn gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%CVE-2026-21372HIGHHeap-Based Buffer Overflow in Power Management ICEPSS 0.1%CVE-2026-45531HIGHIn read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of EPSS 0.1%CVE-2026-55294HIGHIn ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to locaEPSS 0.1%CVE-2026-45515HIGHIn a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overfEPSS 0.1%CVE-2026-1652MEDIUMA potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local autheEPSS 0.1%CVE-2026-61464LOWImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11EPSS 0.1%CVE-2026-15174MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.1%CVE-2024-27209HIGHthere is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional eEPSS 0.1%CVE-2026-24922MEDIUMBuffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%