Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-69347HIGHWindows Fast FAT Driver Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-20766HIGHMilesight Cameras Heap-based Buffer OverflowEPSS 0.3%CVE-2023-21733HIGHWindows Bind Filter Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-31280HIGHA memory corruption issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafteEPSS 0.3%CVE-2025-55648MEDIUMA heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause EPSS 0.3%CVE-2025-55645MEDIUMA heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of SeEPSS 0.3%CVE-2025-8879HIGHHeap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption viaEPSS 0.3%CVE-2023-28523HIGHIBM Informix Dynamic Server buffer overflowEPSS 0.3%CVE-2026-0200HIGHIn Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege EPSS 0.3%CVE-2026-1283HIGHHeap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026EPSS 0.3%CVE-2026-0132HIGHIn Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additionalEPSS 0.3%CVE-2022-43655HIGHBentley View FBX File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-0149HIGHIn RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution withEPSS 0.3%CVE-2021-25495HIGHA possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitraEPSS 0.3%CVE-2025-29769HIGHlibvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF outputEPSS 0.3%CVE-2025-5517MEDIUMHeap Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-42851HIGHBuffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.EPSS 0.3%CVE-2025-61829HIGHIllustrator on iPad | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2025-3548MEDIUMOpen Asset Import Library Assimp File types.h Set heap-based overflowEPSS 0.3%CVE-2025-11458HIGHHeap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via aEPSS 0.3%