Falhas do tipo CWE-122

3.210 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2026-30982MEDIUMiccDEV has a heap out-of-bounds read in CIccPcsXform::pushXYZConvert()EPSS 0.2%CVE-2024-52059MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.EPSS 0.2%CVE-2025-57107HIGHKitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing spEPSS 0.2%CVE-2023-20029MEDIUMCisco IOS XE Software Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-5040HIGHRTE File Parsing Heap-Based Overflow VulnerabilityEPSS 0.2%CVE-2026-56967HIGHIn Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) codeEPSS 0.2%CVE-2026-28662HIGHIn p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead tEPSS 0.2%CVE-2025-46269HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Heap-based Buffer OverflowEPSS 0.2%CVE-2025-52584HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Heap-based Buffer OverflowEPSS 0.2%CVE-2025-49850HIGHOut-of-bounds Read in Write in LS Electric GMWin 4EPSS 0.2%CVE-2026-54896LOWOj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large IndentEPSS 0.2%CVE-2026-58097HIGHppp(8): missing length validation in mp_SetEnddisc()EPSS 0.2%CVE-2026-34534MEDIUMiccDEV: HBO in CIccMpeSpectralMatrix::Describe()EPSS 0.2%CVE-2024-27372MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-4657HIGHA buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, LenEPSS 0.2%CVE-2026-58306MEDIUMHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525EPSS 0.2%CVE-2025-8351HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed fileEPSS 0.2%CVE-2026-18370MEDIUMHeap-based buffer overflow in entrEPSS 0.2%CVE-2025-5043HIGH3DM File Parsing Heap-Based Overflow VulnerabilityEPSS 0.2%CVE-2026-91088LOWGPAC URL url.c gf_url_concatenate_ex heap-based overflowEPSS 0.2%