Falhas do tipo CWE-122

3.189 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2024-37977HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2024-22532MEDIUMBuffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.EPSS 1.1%CVE-2023-29073A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malEPSS 1.1%CVE-2025-59254HIGHMicrosoft DWM Core Library Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2025-23123CRITICALA malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow vulEPSS 1.1%CVE-2025-29912HIGHCryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurityEPSS 1.1%CVE-2024-38051HIGHWindows Graphics Component Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-32093HIGHWindows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2025-21413HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-21339HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-21409HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-21411HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-62456HIGHWindows Resilient File System (ReFS) Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-25588HIGHRedisTimeSeries RESTORE invalid memory access may allow remote code executionEPSS 1.1%CVE-2026-20922HIGHWindows NTFS Remote Code Execution VulnerabilityEPSS 1.1%CVE-2021-21958HIGHA heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-craEPSS 1.1%CVE-2023-21783HIGH3D Builder Remote Code Execution VulnerabilityEPSS 1.1%CVE-2024-33429HIGHBuffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wavEPSS 1.1%CVE-2024-43480MEDIUMAzure Service Fabric for Linux Remote Code Execution VulnerabilityEPSS 1.1%CVE-2022-40655HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. UEPSS 1.1%