Falhas do tipo CWE-122

3.209 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2023-0208HIGH NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow throughEPSS 0.2%CVE-2026-53720MEDIUMpymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too smallEPSS 0.2%CVE-2026-11143MEDIUMOut of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maliEPSS 0.2%CVE-2026-11824HIGHSQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterateEPSS 0.2%CVE-2023-32461MEDIUM Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potEPSS 0.2%CVE-2026-34535MEDIUMiccDEV: SEGV in CIccTagArray::Cleanup()EPSS 0.2%CVE-2026-52834HIGHjxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platformsEPSS 0.2%CVE-2026-79591HIGHA heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation oEPSS 0.2%CVE-2026-34539MEDIUMiccDEV: HBO in CTiffImg::WriteLine()EPSS 0.2%CVE-2026-9123HIGHHeap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute EPSS 0.2%CVE-2026-34540MEDIUMiccDEV: HBO in icMemDump()EPSS 0.2%CVE-2024-21594MEDIUMJunos OS: SRX 5000 Series: Repeated execution of a specific CLI command causes a flowd crashEPSS 0.2%CVE-2025-15668MEDIUMGPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflowEPSS 0.2%CVE-2026-19781HIGHAshlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-3713MEDIUMpnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflowEPSS 0.2%CVE-2026-48914MEDIUMQemu-kvm: heap buffer overflow in virtio-blk scsi request handlingEPSS 0.2%CVE-2026-14610MEDIUMOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflowEPSS 0.2%CVE-2026-3407MEDIUMYosysHQ yosys BLIF File rtlil.h set heap-based overflowEPSS 0.2%CVE-2025-8894HIGHPDF File Parsing Heap-Based Buffer Overflow VulnerabilityEPSS 0.2%CVE-2026-13574MEDIUMllvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflowEPSS 0.2%