Falhas do tipo CWE-122

3.195 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2023-24014HIGHDelta Electronics CNCSoft-B DOPSoft Heap-based buffer overflowEPSS 0.2%CVE-2023-37247HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2026-18296HIGHGStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-0633MEDIUMHeap Overflow in iniparser.cEPSS 0.2%CVE-2026-29022MEDIUMmackron / dr_libs dr_wav.h Heap Buffer Overflow via WAV FileEPSS 0.2%CVE-2024-10204HIGHHeap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025EPSS 0.2%CVE-2024-7673HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2025-47099HIGHInCopy | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-47131HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2024-7674HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2025-7207MEDIUMmruby nregs codegen.c scope_new heap-based overflowEPSS 0.2%CVE-2024-8587HIGHAutodesk AutoCAD SLDPRT File Parsing Heap-based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2025-47125HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2026-3393MEDIUMjarikomppa soloud Audio File soloud_wav.cpp loadflac heap-based overflowEPSS 0.2%CVE-2025-47122HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-47123HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2025-3512MEDIUMBuffer overflow in QTextMarkdownImporterEPSS 0.2%CVE-2025-54282HIGHAdobe Framemaker | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2026-2661MEDIUMSquirrel sqobject.h operator heap-based overflowEPSS 0.2%CVE-2022-29210MEDIUMHeap buffer overflow due to incorrect hash function in TensorFlowEPSS 0.2%