Fallos del tipo CWE-122

3195 resultados

Estouro de heap

É quando o código escreve dados além dos limites de um buffer alocado no heap (memória dinâmica), sobrescrevendo dados de outras estruturas adjacentes. Esse estouro pode corromper metadados do heap, variáveis vizinhas ou objetos do programa, permitindo execução de código arbitrário ou negação de serviço.

Ejemplo

Um servidor web recebe uma string de tamanho arbitrário e a copia para um buffer de 256 bytes sem validar o comprimento (ex: strcpy em C). Se o atacante enviar 500 bytes, o restante escreve além da zona alocada, corrompendo estruturas próximas e potencialmente ganhando controle do fluxo.

Cómo mitigar

Use funções seguras (strncpy, strlcpy, snprintf em C) que respeitam limites de tamanho; valide e sanitize entrada do usuário antes de copiar; ative proteções do SO (ASLR, DEP/NX); use linguagens de memória segura quando possível; aplique verificações de limites em loops de cópia.

CVE-2024-20508MEDIUMCisco UTD Snort IPS Engine Software for Cisco IOS XE Software Security Policy Bypass and Denial of Service VulnerabilityEPSS 0.4%CVE-2025-1049HIGHSonos Era 300 Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25664HIGHTensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad EPSS 0.4%CVE-2025-0611HIGHObject corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.4%CVE-2024-27340HIGHKofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-7508HIGHTrimble SketchUp Viewer SKP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-27341HIGHKofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-59186HIGHOpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow on 32-bit (ILP32) buildsEPSS 0.4%CVE-2026-75619MEDIUMRTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101EPSS 0.4%CVE-2026-77532CRITICALA malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwiEPSS 0.4%CVE-2023-40166MEDIUMNotepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining EPSS 0.4%CVE-2026-20053MEDIUMCisco Secure Firewall Threat Defense Software Snort 3 Visual Basic for Application Heap Overflow Denial of Service VulnerabilityEPSS 0.4%CVE-2024-27243MEDIUMZoom Apps - Buffer OverflowEPSS 0.4%CVE-2025-52869LOWQsync CentralEPSS 0.4%CVE-2026-34979MEDIUMOpenPrinting CUPS: Heap overflow in `get_options()`EPSS 0.4%CVE-2023-26416HIGHZDI-CAN-20318: Adobe Substance 3D Designer DAE File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-25897MEDIUMImageMagick has heap overflow in sun decoder on 32-bit systems that can result in out of bounds writeEPSS 0.4%CVE-2023-26413HIGHZDI-CAN-20315: Adobe Substance 3D Designer USD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-25872HIGHAdobe Substance 3D Stager SVG File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26394HIGHZDI-CAN-20236: Adobe Substance 3D Stager USD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%