Falhas do tipo CWE-122

3.209 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-68514MEDIUMOpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep imagesEPSS 0.2%CVE-2026-61714HIGHFluidSynth: Heap Buffer Overflow in MIDI PlayerEPSS 0.2%CVE-2026-12030HIGHOut of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2025-54496HIGHFuji Electric Monitouch V-SFT-6 Heap-based Buffer OverflowEPSS 0.2%CVE-2026-0130MEDIUMIn RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information dEPSS 0.2%CVE-2026-27799MEDIUMImageMagick has a heap Buffer Over-read in its DJVU image format handlerEPSS 0.2%CVE-2026-42309MEDIUMPillow: Heap buffer overflow with nested list coordinatesEPSS 0.2%CVE-2025-1218LOWVarious packet overreads in mysqlnd_writeprotocol.cEPSS 0.2%CVE-2025-6490MEDIUMsparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflowEPSS 0.2%CVE-2026-27940HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 FixEPSS 0.2%CVE-2025-46333HIGHz2d OOB composition could lead to invalid memory access and corruptionEPSS 0.2%CVE-2025-11947LOWbftpd Configuration File options.c expand_groups heap-based overflowEPSS 0.2%CVE-2025-6494MEDIUMsparklemotion nokogiri hashmap.c hashmap_get_with_hash heap-based overflowEPSS 0.2%CVE-2026-90577MEDIUMGPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflowEPSS 0.2%CVE-2026-68765MEDIUMhashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token FieldEPSS 0.2%CVE-2026-46655HIGHvirtio-win: Integer overflow causing a heap overflow in Viosock driverEPSS 0.2%CVE-2025-48990HIGHNeKernel has Heap Overflow in `rt_copy_memory`EPSS 0.2%CVE-2026-35591HIGHPossible heap-based buffer overflow when decoding TIFF image containing well-crafted tileEPSS 0.2%CVE-2025-64031LOWlibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressEPSS 0.2%CVE-2026-45761LOWSuricata detect: case-insensitive frame handling can cause heap buffer overflow during rule loadEPSS 0.2%