Fallos del tipo CWE-119

3271 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-1163MEDIUMcode-projects Vehicle Parking Management System Authentication login stack-based overflowEPSS 0.5%CVE-2022-25310—A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c EPSS 0.5%CVE-2025-2750MEDIUMOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds writeEPSS 0.5%CVE-2022-20601HIGHProduct: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/AEPSS 0.5%CVE-2022-20602HIGHProduct: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/AEPSS 0.5%CVE-2026-11553HIGHTenda HG7HG9/HG10 formPPPEdit stack-based overflowEPSS 0.5%CVE-2026-10188HIGHTenda W12 httpd cgistaKickOff stack-based overflowEPSS 0.5%CVE-2026-11557HIGHTenda F451 Web Management Natlimit fromNatlimit stack-based overflowEPSS 0.5%CVE-2026-0878HIGHSandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2026-10191HIGHTenda W12 httpd cgiWifiMacFilterSet stack-based overflowEPSS 0.5%CVE-2022-0496—A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-oEPSS 0.5%CVE-2025-3407MEDIUMNothings stb stbhw_build_tileset_from_image out-of-boundsEPSS 0.5%CVE-2026-10122HIGHTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowEPSS 0.5%CVE-2026-10181HIGHTRENDnet TEW-432BRP formSysCmd stack-based overflowEPSS 0.5%CVE-2026-10162HIGHTRENDnet TEW-432BRP formSetPassword stack-based overflowEPSS 0.5%CVE-2025-24222MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web contentEPSS 0.5%CVE-2026-10183HIGHTRENDnet TEW-432BRP formWlanSetup stack-based overflowEPSS 0.5%CVE-2026-10119HIGHTRENDnet TEW-432BRP formSetMACFilter stack-based overflowEPSS 0.5%CVE-2026-10292HIGHUTT HiPER 1200GW formTaskEdit strcpy stack-based overflowEPSS 0.5%CVE-2026-10293HIGHUTT HiPER 1200GW formFireWall strcpy stack-based overflowEPSS 0.5%