Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-24283HIGHMultiple UNC Provider Kernel Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-3463MEDIUMGE Digital CIMPLICITY Heap-based Buffer OverflowEPSS 0.4%CVE-2023-47056HIGHZDI-CAN-21763: Adobe Premiere Pro MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-5750HIGHWOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-21337MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2026-3082HIGHGStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-76886HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.4%CVE-2023-39492HIGHPDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-47051MEDIUMZDI-CAN-21683: Adobe Audition MP4 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-6361HIGHHeap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage EPSS 0.4%CVE-2024-22058HIGHA buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated EPSS 0.4%CVE-2024-39392HIGHAdobe Indesign 2024 EPS File Parsing Heap Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-61390HIGHThere is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunctiEPSS 0.4%CVE-2024-52996HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-49705HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-52995HIGHSubstance3D - Sampler | Heap-based Buffer Overflow (CWE-122)EPSS 0.4%CVE-2025-5477HIGHSony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-5479HIGHSony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-1275HIGHJPG File Parsing Heap-Based Overflow VulnerabilityEPSS 0.4%