Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-69578HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-22100HIGHMicroDicom DICOM Heap-based Buffer OverflowEPSS 0.3%CVE-2025-48797HIGHGimp: multiple heap buffer overflows in tga parserEPSS 0.3%CVE-2021-21572HIGHDell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system mayEPSS 0.3%CVE-2026-12010HIGHHeap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2025-20720HIGHIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) eEPSS 0.3%CVE-2022-45491HIGHBuffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (NovembeEPSS 0.3%CVE-2025-31344HIGHThe giflib open-source component has a buffer overflow vulnerabilityEPSS 0.3%CVE-2025-54244HIGHSubstance3D - Viewer | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2026-88807HIGHlibXrender RenderQueryPictFormats Reply Heap-based Buffer OverflowEPSS 0.3%CVE-2023-37297HIGHheap memory overflow EPSS 0.3%CVE-2025-21129HIGHSubstance3D - Stager | Heap-based Buffer Overflow (CWE-122)EPSS 0.3%CVE-2023-37295HIGHHeap-based Buffer OverflowEPSS 0.3%CVE-2026-8560MEDIUMHeap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bEPSS 0.3%CVE-2025-7033HIGHRockwell Automation Heap-based Buffer Overflow In Arena® SimulationEPSS 0.3%CVE-2025-7025HIGHRockwell Automation Heap-based Buffer Overflow In Arena® SimulationEPSS 0.3%CVE-2025-65018HIGHLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`EPSS 0.3%CVE-2023-37294HIGHHeap-based Buffer OverflowEPSS 0.3%CVE-2024-56827MEDIUMOpenjpeg: heap buffer overflow in lib/openjp2/j2k.cEPSS 0.3%CVE-2025-6499MEDIUMvstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflowEPSS 0.3%