Falhas do tipo CWE-122

3.192 resultados

Estouro de heap

Ocorre quando código escreve mais dados do que o espaço alocado em uma região de memória dinâmica (heap), sobrescrevendo dados adjacentes. Um atacante pode explorar isso para corromper estruturas de dados críticas, contornar proteções de segurança ou executar código arbitrário.

Exemplo

Um servidor web aloca 256 bytes para armazenar um nome de usuário, mas copia 512 bytes de uma requisição sem validação. Os 256 bytes extras sobrescrevem ponteiros ou metadados do heap, permitindo execução de código ou negação de serviço.

Como mitigar

Use funções seguras que respeitam limites (strcpy_s, memcpy com tamanho verificado em runtime). Validar e limitar o tamanho de entrada antes de copiar. Ativar proteções como ASLR, stack canaries e ferramentas de sanitização (AddressSanitizer) em desenvolvimento.

CVE-2024-42436MEDIUMZoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer OverflowEPSS 0.6%CVE-2024-42437MEDIUMZoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer OverflowEPSS 0.6%CVE-2026-87430HIGHBuffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside theEPSS 0.6%CVE-2026-87579HIGHBuffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox viaEPSS 0.6%CVE-2026-5858HIGHHeap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTMLEPSS 0.6%CVE-2026-9939HIGHHeap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.6%CVE-2024-50698CRITICALSunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message coEPSS 0.6%CVE-2026-34743LOWXZ Utils: Buffer overflow in lzma_index_append()EPSS 0.6%CVE-2026-76034HIGHBuffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox viEPSS 0.6%CVE-2026-78891HIGHBuffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox viaEPSS 0.6%CVE-2021-25387CRITICALAn improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackerEPSS 0.6%CVE-2025-24995HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-55130HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55033HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-45475HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-48691HIGHFastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IEPSS 0.6%CVE-2026-44824HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55125HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55127HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-44819HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.6%