Falhas do tipo CWE-122

3.210 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2022-36863MEDIUMA heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SEPSS 0.1%CVE-2022-36844MEDIUMA heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-EPSS 0.1%CVE-2022-36846MEDIUMA heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-202EPSS 0.1%CVE-2022-36841MEDIUMA heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR SeEPSS 0.1%CVE-2022-36845MEDIUMA heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022EPSS 0.1%CVE-2022-36860MEDIUMA heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 ReEPSS 0.1%CVE-2022-36862MEDIUMA heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR SeEPSS 0.1%CVE-2026-88386MEDIUMlibsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV fiEPSS 0.1%CVE-2025-32325HIGHIn appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of pEPSS 0.1%CVE-2026-41981MEDIUMOut-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-21104HIGHHeap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary codeEPSS 0.1%CVE-2026-23788MEDIUMAn issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due toEPSS 0.1%CVE-2025-26455HIGHIn multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%CVE-2026-45515HIGHIn a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overfEPSS 0.1%CVE-2026-49932HIGHIn parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation oEPSS 0.1%CVE-2026-21372HIGHHeap-Based Buffer Overflow in Power Management ICEPSS 0.1%CVE-2026-55323HIGHIn gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local EPSS 0.1%CVE-2026-58820HIGHIn multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege witEPSS 0.1%CVE-2026-45531HIGHIn read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of EPSS 0.1%CVE-2026-55294HIGHIn ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to locaEPSS 0.1%