Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-13587MEDIUMseladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflowEPSS 0.7%CVE-2025-14425HIGHGIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-23378HIGHPrint 3D Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-62458HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2023-23390HIGH3D Builder Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-31806CRITICALFreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap DimensionsEPSS 0.7%CVE-2024-56732CRITICALHarfBuzz heap-buffer-overflow on hb_cairo_glyphs_from_bufferEPSS 0.7%CVE-2026-5402HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.7%CVE-2025-47169HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-57637HIGHBuffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowingEPSS 0.7%CVE-2023-49600HIGHAn out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can EPSS 0.7%CVE-2023-23377HIGH3D Builder Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-26061HIGHA heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file canEPSS 0.6%CVE-2025-40907MEDIUMFCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) libraryEPSS 0.6%CVE-2025-21375HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2021-3903HIGHHeap-based Buffer Overflow in vim/vimEPSS 0.6%CVE-2026-64830HIGHFFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle DemuxerEPSS 0.6%CVE-2026-25646HIGHLIBPNG has a heap buffer overflow in png_set_quantizeEPSS 0.6%CVE-2023-27911HIGHA user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or EPSS 0.6%CVE-2022-38404HIGHAdobe InCopy SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%