Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2026-82820MEDIUMFLVMeta AMF String Processing amf.c amf_string_new heap-based overflowEPSS 0.6%CVE-2024-30066MEDIUMWinlogon Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-39825HIGHZoom Workplace Apps and Rooms Clients - Buffer OverflowEPSS 0.6%CVE-2024-6383MEDIUMMongoDB C Driver bson_string_append may be vulnerable to a buffer overflowEPSS 0.6%CVE-2026-4153HIGHGIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2447HIGHHeap buffer overflow in libvpxEPSS 0.6%CVE-2024-6994HIGHHeap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.6%CVE-2024-48075MEDIUMA Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attEPSS 0.6%CVE-2023-28269MEDIUMWindows Boot Manager Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-81477HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attEPSS 0.6%CVE-2026-29004HIGHBusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERSEPSS 0.6%CVE-2026-63633HIGHFreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→clientEPSS 0.6%CVE-2026-55194HIGHFreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatchEPSS 0.6%CVE-2024-37280MEDIUMElasticsearch StackOverflow vulnerabilityEPSS 0.6%CVE-2024-5160HIGHHeap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via EPSS 0.6%CVE-2026-56003HIGHlibXfont2 computeProps Property Buffer Heap Buffer OverflowEPSS 0.6%CVE-2024-49072HIGHWindows Task Scheduler Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-56001HIGHlibXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer OverflowEPSS 0.6%CVE-2026-2049HIGHGIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-21354HIGHMicrosoft Message Queuing (MSMQ) Elevation of Privilege VulnerabilityEPSS 0.6%