Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-44050CRITICALHeap buffer overflow in CNID daemon comm_rcv()EPSS 0.7%CVE-2021-3770HIGHHeap-based Buffer Overflow in vim/vimEPSS 0.7%CVE-2024-2824MEDIUMMatthias-Wandel jhead exif.c PrintFormatNumber heap-based overflowEPSS 0.7%CVE-2024-43626HIGHWindows Telephony Service Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-38411HIGHAdobe Animate SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-56737HIGHGNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.EPSS 0.7%CVE-2023-26793CRITICALlibmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.EPSS 0.7%CVE-2026-30999HIGHA heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a craftEPSS 0.7%CVE-2025-49744HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-72970HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-45591HIGHA CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated aEPSS 0.7%CVE-2025-2592MEDIUMOpen Asset Import Library Assimp CSMLoader.cpp InternReadFile heap-based overflowEPSS 0.7%CVE-2025-66217HIGHAIS-catcher Integer Underflow in MQTT Packet Parsing leading to Heap Buffer OverflowEPSS 0.7%CVE-2024-41147HIGHAn out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A speciallEPSS 0.7%CVE-2026-67873CRITICALA heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegmEPSS 0.7%CVE-2021-25360CRITICALAn improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitraryEPSS 0.7%CVE-2023-5404HIGHServer receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See HoneyEPSS 0.7%CVE-2023-21737HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-69325HIGHMicrosoft JScript Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-32026HIGHMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 0.7%