Fallos del tipo CWE-119

3271 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-14673MEDIUMgmg137 snap7-rs client.rs as_ct_write heap-based overflowEPSS 0.5%CVE-2025-14672MEDIUMgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflowEPSS 0.5%CVE-2023-49701HIGHOut-of-bounds access a buffer in SIM managementEPSS 0.5%CVE-2025-4472MEDIUMcode-projects Departmental Store Management System bill stack-based overflowEPSS 0.5%CVE-2021-3409—The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access EPSS 0.5%CVE-2024-8389CRITICALMemory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2021-3507—A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() inEPSS 0.5%CVE-2025-5268HIGHMemory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11EPSS 0.5%CVE-2026-28935HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2023-43817HIGHDelta Electronics Delta Industrial Automation DOPSoft DPS File wMailContentLen Buffer Overflow Remote Code ExecutionEPSS 0.5%CVE-2025-2753MEDIUMOpen Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-boundsEPSS 0.5%CVE-2024-3865HIGHMemory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2023-1579HIGHHeap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.EPSS 0.5%CVE-2026-28944HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visioEPSS 0.5%CVE-2026-10259HIGHH3C Magic B0 aspForm SetMobileAPInfoById stack-based overflowEPSS 0.5%CVE-2025-4093HIGHMemory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10EPSS 0.5%CVE-2026-9365MEDIUMEttercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflowEPSS 0.5%CVE-2025-1864CRITICALBuffer Overflow and Potential Code Execution in Radare2EPSS 0.5%CVE-2026-0891HIGHMemory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2026-11413HIGHJingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflowEPSS 0.5%