Fallos del tipo CWE-119

3270 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-13522MEDIUMInvestintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-boundsEPSS 0.5%CVE-2023-30774—A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROEPSS 0.5%CVE-2026-18585MEDIUMGL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflowEPSS 0.5%CVE-2026-28955HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28902MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2026-28901MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2024-22041HIGHA vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions),EPSS 0.5%CVE-2019-1771HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilityEPSS 0.5%CVE-2025-2756MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflowEPSS 0.5%CVE-2026-28847HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28903MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2022-3628MEDIUMA buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious UEPSS 0.5%CVE-2025-14330CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2024-9400HIGHA potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during EPSS 0.5%CVE-2024-14043MEDIUMOpen5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflowEPSS 0.5%CVE-2024-14044MEDIUMOpen5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflowEPSS 0.5%CVE-2022-23813MEDIUMThe software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest meEPSS 0.5%CVE-2025-3015MEDIUMOpen Asset Import Library Assimp ASE File ASELoader.cpp BuildUniqueRepresentation out-of-boundsEPSS 0.5%CVE-2026-0821MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_constructor heap-based overflowEPSS 0.5%CVE-2024-14042MEDIUMOpen5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflowEPSS 0.5%