Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2024-20745HIGHZDI-CAN-22671: Adobe Premiere Pro AVI File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-21596MEDIUMJunos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devicesEPSS 0.5%CVE-2026-32945HIGHPJSIP is vulnerable to Heap-based Buffer Overflow through DNS parserEPSS 0.5%CVE-2020-15198MEDIUMHeap buffer overflow in TensorflowEPSS 0.5%CVE-2025-0870MEDIUMAxiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflowEPSS 0.5%CVE-2024-2212HIGHInteger wraparounds, under-allocations, and heap buffer overflows in Eclipse ThreadX xQueueCreate() and xQueueCreateSet()EPSS 0.5%CVE-2025-2754MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflowEPSS 0.5%CVE-2023-4692HIGHGrub2: out-of-bounds write at fs/ntfs.c may lead to unsigned code executionEPSS 0.5%CVE-2025-32717HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-50176HIGHDirectX Graphics Kernel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-10921HIGHGIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-10934HIGHGIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-22660HIGHA heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record typEPSS 0.5%CVE-2026-42975HIGHWindows Bluetooth Port Driver Remote Code ExecutionEPSS 0.5%CVE-2024-50571MEDIUMA heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7EPSS 0.5%CVE-2024-56406HIGHPerl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytesEPSS 0.5%CVE-2022-42403HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.5%CVE-2026-62816HIGHWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-62823HIGHWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-42904CRITICALWindows TCP/IP Elevation of Privilege VulnerabilityEPSS 0.5%