Fallos del tipo CWE-119

3271 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-10160HIGHTRENDnet TEW-432BRP formSetEnableWizard stack-based overflowEPSS 0.5%CVE-2026-10122HIGHTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowEPSS 0.5%CVE-2025-9185HIGHMemory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.5%CVE-2025-24222MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web contentEPSS 0.5%CVE-2026-10119HIGHTRENDnet TEW-432BRP formSetMACFilter stack-based overflowEPSS 0.5%CVE-2026-10123HIGHTRENDnet TEW-432BRP formSetDomainFilter stack-based overflowEPSS 0.5%CVE-2026-82618MEDIUMSysterel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-boundsEPSS 0.5%CVE-2026-7322HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2022-1778HIGHA vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ...EPSS 0.5%CVE-2026-19999MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-86514MEDIUMvgmstream txth-txtp txth.c sscanf stack-based overflowEPSS 0.5%CVE-2026-12805MEDIUMOFFIS DCMTK ofxml.cc parseFile heap-based overflowEPSS 0.5%CVE-2024-22170CRITICALUnchecked buffer in Dynamic DNS clientEPSS 0.5%CVE-2026-16360CRITICALMemory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153EPSS 0.5%CVE-2026-64757HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.5%CVE-2025-26265MEDIUMA segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification EPSS 0.5%CVE-2026-20268HIGHCisco IOS XE Software Security Hardening ReleaseEPSS 0.5%CVE-2026-20319HIGHCisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management VulnerabilitiesEPSS 0.5%CVE-2026-11522HIGHTenda W20E setPortMirror formSetPortMirror stack-based overflowEPSS 0.5%CVE-2026-11523HIGHTenda W20E Web Management PortalAuth formPortalAuth stack-based overflowEPSS 0.5%