Falhas do tipo CWE-122

3.210 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2024-10253MEDIUMA potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to causeEPSS 0.1%CVE-2021-25475LOWA possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and cEPSS 0.1%CVE-2024-0018HIGHIn convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could leadEPSS 0.1%CVE-2026-15164MEDIUMHeap-based Buffer Overflow in ciscodumpEPSS 0.1%CVE-2025-11961LOWOOBR and OOBW in pcap_ether_aton() in libpcapEPSS 0.1%CVE-2022-44427MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-18495MEDIUMLibtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthroughEPSS 0.1%CVE-2025-20731MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-15449MEDIUMTOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruptionEPSS 0.1%CVE-2025-20734MEDIUMIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-0059HIGHIn multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead EPSS 0.1%CVE-2026-21399MEDIUMHeap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0EPSS 0.1%CVE-2026-28546MEDIUMBuffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2024-49714HIGHIn avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device eEPSS 0.1%CVE-2026-62381MEDIUMluci-lib-px5g 2040-bit Certificate Signing Heap Buffer OverflowEPSS 0.1%CVE-2025-62624HIGHA heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially EPSS 0.1%CVE-2022-36858MEDIUMA heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior toEPSS 0.1%CVE-2022-36842MEDIUMA heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-202EPSS 0.1%CVE-2022-36863MEDIUMA heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SEPSS 0.1%CVE-2022-36841MEDIUMA heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR SeEPSS 0.1%