Falhas do tipo CWE-122

3.202 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-39113MEDIUMBuffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f10695EPSS 0.2%CVE-2026-28420MEDIUMVim has Heap-based Buffer Overflow and OOB Read in :terminalEPSS 0.2%CVE-2026-40169MEDIUMImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encodersEPSS 0.2%CVE-2026-40310MEDIUMImageMagick: Heap out-of-bounds write in JP2 encoderEPSS 0.2%CVE-2026-2467CRITICALHeap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2025-11464HIGHAshlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-5403HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2026-5405HIGHHeap-based Buffer Overflow in WiresharkEPSS 0.2%CVE-2024-22453HIGHDell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit tEPSS 0.2%CVE-2026-25205HIGHHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash EPSS 0.2%CVE-2026-25576MEDIUMImageMagick: Out of bounds read in multiple coders read raw pixel dataEPSS 0.2%CVE-2026-55893HIGHCapstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecodeEPSS 0.2%CVE-2026-75649HIGHBridge | Heap-based Buffer Overflow (CWE-122)EPSS 0.2%CVE-2026-56392LOWHeap-based Buffer Overflow in GNU coreutilsEPSS 0.2%CVE-2024-6031HIGHTesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution VulnerabilityEPSS 0.2%CVE-2026-63422HIGHOpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds writeEPSS 0.2%CVE-2026-8484MEDIUMHeap buffer overflow in JansiEPSS 0.2%CVE-2026-15520MEDIUMGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2026-8997MEDIUMHeap Buffer Overflow in vifmEPSS 0.2%CVE-2026-15182MEDIUMGNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflowEPSS 0.2%