Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2025-65406MEDIUMA heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to causeEPSS 0.3%CVE-2026-10989HIGHInappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in speciEPSS 0.3%CVE-2025-11788HIGHHeap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.3%CVE-2024-39380HIGHAfter Effects | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-25390HIGHA heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2025-24453HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-27171HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-27177HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2024-8443LOWLibopensc: heap buffer overflow in openpgp driver when generating keyEPSS 0.3%CVE-2024-8025HIGHNikon NEF Codec Thumbnail Provider NRW File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-32401MEDIUMAn Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the EPSS 0.3%CVE-2018-8834—Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prEPSS 0.3%CVE-2023-4682MEDIUMHeap-based Buffer Overflow in gpac/gpacEPSS 0.3%CVE-2025-53630HIGHInteger Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in ggufEPSS 0.3%CVE-2026-31883MEDIUMFreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow writeEPSS 0.3%CVE-2025-59191HIGHWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-47311HIGHHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258EPSS 0.3%CVE-2025-30644HIGHJunos OS: EX2300, EX3400, EX4000 Series, QFX5k Series: Receipt of a specific DHCP packet causes FPC crash when DHCP Option 82 is enabledEPSS 0.3%CVE-2022-39136HIGHA vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamceEPSS 0.3%CVE-2025-11205HIGHHeap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process toEPSS 0.3%