Falhas do tipo CWE-122

3.202 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2024-41981HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2021-26330—AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.EPSS 0.2%CVE-2026-3463MEDIUMxlnt-community xlnt Compound Document binary.hpp append heap-based overflowEPSS 0.2%CVE-2025-61154MEDIUMHeap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of ServiEPSS 0.2%CVE-2025-3791MEDIUMsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflowEPSS 0.2%CVE-2025-70302MEDIUMA heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted EPSS 0.2%CVE-2023-24551HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-43688HIGHAn issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encEPSS 0.2%CVE-2023-24550HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2025-70303MEDIUMA heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 filEPSS 0.2%CVE-2025-11206HIGHHeap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.2%CVE-2025-15537MEDIUMMapnik dbfile.cpp string_value heap-based overflowEPSS 0.2%CVE-2026-21491MEDIUMiccDEV has unicode buffer overflow in CIccTagTextDescriptionEPSS 0.2%CVE-2026-21490MEDIUMiccDEV has heap buffer overflow in CIccTagLut16::Validate()EPSS 0.2%CVE-2025-50130HIGHA heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC CO., LTD. Opening VEPSS 0.2%CVE-2025-14956MEDIUMWebAssembly Binaryen wasm-binary.cpp readExport heap-based overflowEPSS 0.2%CVE-2026-21504MEDIUMHeap Buffer Overflow in iccDEV ToneMap ParserEPSS 0.2%CVE-2023-40465HIGHImproper input leads to DoSEPSS 0.2%CVE-2025-31164MEDIUMfig2dev heap-buffer overflowEPSS 0.2%CVE-2025-1273HIGHPDF File Parsing Heap-Based Overflow VulnerabilityEPSS 0.2%