Fallos del tipo CWE-119

3271 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-10189HIGHTenda W12 httpd cgiSysTimeInfoSet stack-based overflowEPSS 0.5%CVE-2026-10192HIGHTenda W12 httpd set_local_time_0 stack-based overflowEPSS 0.5%CVE-2026-28940HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.5%CVE-2023-44184MEDIUMJunos OS and Junos OS Evolved: High CPU load due to specific NETCONF commandEPSS 0.5%CVE-2023-28581CRITICALImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN FirmwareEPSS 0.5%CVE-2026-19969MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-10206HIGHD-Link DI-8400 dbsrv.asp stack-based overflowEPSS 0.5%CVE-2025-2584LOWWebAssembly wabt binary-reader-interp.cc GetReturnCallDropKeepCount heap-based overflowEPSS 0.5%CVE-2026-28911CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be EPSS 0.5%CVE-2021-1131MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.5%CVE-2025-4091HIGHMemory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10EPSS 0.5%CVE-2026-7668MEDIUMMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-boundsEPSS 0.5%CVE-2026-0886MEDIUMIncorrect boundary conditions in the Graphics componentEPSS 0.5%CVE-2022-32455HIGHTMM vulnerability CVE-2022-32455EPSS 0.5%CVE-2025-0751MEDIUMAxiomatic Bento4 mp42aac ReadBits heap-based overflowEPSS 0.5%CVE-2026-16411CRITICALMemory safety bugs fixed in Firefox 153EPSS 0.5%CVE-2026-12292HIGHIncorrect boundary conditions in the Web Audio componentEPSS 0.5%CVE-2025-14672MEDIUMgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflowEPSS 0.5%CVE-2022-3213—A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavEPSS 0.5%CVE-2025-14673MEDIUMgmg137 snap7-rs client.rs as_ct_write heap-based overflowEPSS 0.5%