Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2024-42437MEDIUMZoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer OverflowEPSS 0.6%CVE-2026-87430HIGHBuffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside theEPSS 0.6%CVE-2026-87579HIGHBuffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox viaEPSS 0.6%CVE-2026-5858HIGHHeap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTMLEPSS 0.6%CVE-2026-9939HIGHHeap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.6%CVE-2024-50698CRITICALSunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message coEPSS 0.6%CVE-2026-34743LOWXZ Utils: Buffer overflow in lzma_index_append()EPSS 0.6%CVE-2026-78891HIGHBuffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox viaEPSS 0.6%CVE-2026-76034HIGHBuffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox viEPSS 0.6%CVE-2021-25387CRITICALAn improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackerEPSS 0.6%CVE-2025-24995HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-55130HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-45475HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-48691HIGHFastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IEPSS 0.6%CVE-2026-44824HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55127HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-44819HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55125HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55033HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-32177HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.6%