Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-72962HIGHWindows USB Video Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-72961HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69820HIGHWindows Hello Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62881MEDIUMWindows DNS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69350MEDIUMWindows Overlay Filter Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62769MEDIUMWindows DNS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-48592MEDIUMIn initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informEPSS 0.3%CVE-2026-35199MEDIUMSymCrypt SymCryptXmssSign function - Heap overflow via 64->32-bit leaf-count truncationEPSS 0.3%CVE-2026-8531HIGHHeap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corrEPSS 0.3%CVE-2025-21123HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-9940HIGHHeap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.3%CVE-2025-22920MEDIUMA heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a craftedEPSS 0.3%CVE-2026-7339HIGHHeap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.3%CVE-2026-11375HIGHIBM MQ queue manager is vulnerable to remote code executionEPSS 0.3%CVE-2026-15123HIGHInappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruptioEPSS 0.3%CVE-2026-5653MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2026-14415HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in speciEPSS 0.3%CVE-2026-13835HIGHInappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruptionEPSS 0.3%CVE-2026-8834HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.3%CVE-2024-31582HIGHFFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_coEPSS 0.3%