Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2025-20742HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2026-16118HIGHXdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.cEPSS 0.3%CVE-2025-54211HIGHInDesign Desktop | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-69878MEDIUMWindows DHCP Server Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-73017HIGHGraphics Kernel Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-30299HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-34318HIGHHeap-buffer-overflow in src/hcom.cEPSS 0.3%CVE-2023-41140—A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicEPSS 0.3%CVE-2024-9734HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-47964HIGHHeap-based Buffer Overflow vulnerability in Delta Electronics CNCSoft-G2EPSS 0.3%CVE-2024-9741HIGHTungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-7730HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()EPSS 0.3%CVE-2025-22881HIGHHeap-based Buffer Overflow in CNCSoft-G2EPSS 0.3%CVE-2024-9742HIGHTungsten Automation Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2912MEDIUMHDF5 H5Omessage.c H5O_msg_flush heap-based overflowEPSS 0.3%CVE-2025-2923MEDIUMHDF5 H5Fint.c H5F_addr_encode_len heap-based overflowEPSS 0.3%CVE-2025-2914MEDIUMHDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflowEPSS 0.3%CVE-2025-59275HIGHWindows Authentication Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-45679HIGHHeap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a EPSS 0.3%CVE-2026-69242HIGHlibvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident writeEPSS 0.3%