Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2025-58725HIGHWindows COM+ Event System Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-18368MEDIUMHeap buffer overflow in ModbusgwdEPSS 0.3%CVE-2026-19156HIGHHeap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2025-7067MEDIUMHDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflowEPSS 0.3%CVE-2025-7069MEDIUMHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflowEPSS 0.3%CVE-2022-2948HIGHGE CIMPLICITY Heap-based Buffer OverflowEPSS 0.3%CVE-2024-6154HIGHParallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-47107HIGHInCopy | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-36702HIGHlibiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.EPSS 0.2%CVE-2026-10194MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflowEPSS 0.2%CVE-2024-7018HIGHHeap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2025-11275MEDIUMOpen Asset Import Library Assimp OpenDDLParserUtils.h getNextSeparator heap-based overflowEPSS 0.2%CVE-2025-6750MEDIUMHDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflowEPSS 0.2%CVE-2026-18341MEDIUMIBM i is Affected By Buffer Overflow Vulnerability []EPSS 0.2%CVE-2024-32613HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerabEPSS 0.2%CVE-2025-23308LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by gettiEPSS 0.2%CVE-2026-8552MEDIUMHeap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memoryEPSS 0.2%CVE-2024-32620HIGHHDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the inEPSS 0.2%CVE-2026-72927MEDIUMWinsock Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-43582HIGHSubstance3D - Viewer | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%