Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2025-32318HIGHIn Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no adEPSS 0.3%CVE-2026-15169MEDIUMHeap-based Buffer Overflow in WiresharkEPSS 0.3%CVE-2024-13051HIGHAshlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-11822HIGHSQLite before 3.53.2 Memory Corruption in FTS5 ExtensionEPSS 0.3%CVE-2024-7544HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-57807LOWImageMagick BlobStream Forward-Seek Under-AllocationEPSS 0.3%CVE-2024-7543HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2024-13050HIGHAshlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-7545HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-88370MEDIUMlibconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bEPSS 0.3%CVE-2025-61837HIGHFormat Plugins | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-15279HIGHFontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-36763HIGHHeap Buffer Overflow in Tcg2MeasureGptTableEPSS 0.3%CVE-2025-15277HIGHFontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-7546HIGHoFono SimToolKit Heap-based Buffer Overflow Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-21283HIGHBridge | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-24852MEDIUMiccDEV has a heap-buffer-overflow in icXmlParseTextString()EPSS 0.3%CVE-2025-47815MEDIUMlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_EPSS 0.3%CVE-2025-47814MEDIUMlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_EPSS 0.3%CVE-2022-36764HIGHHeap Buffer Overflow in Tcg2MeasurePeImageEPSS 0.3%