Fallos del tipo CWE-119

3272 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-0892CRITICALMemory safety bugs fixed in Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2025-43373HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AEPSS 0.5%CVE-2026-6752HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-6753HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-8973HIGHMemory safety bugs fixed in Firefox 151EPSS 0.5%CVE-2025-2755MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-boundsEPSS 0.5%CVE-2026-8389HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2026-7323HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2022-38692CRITICALIn BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without rEPSS 0.5%CVE-2023-3471HIGHBuffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.5%CVE-2026-43795MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2026-65338MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2026-65334MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10EPSS 0.5%CVE-2022-0367—A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.EPSS 0.5%CVE-2026-65335MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2025-0753MEDIUMAxiomatic Bento4 mp42aac ReadPartial heap-based overflowEPSS 0.5%CVE-2026-65330MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2026-100740CRITICALD-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds writeEPSS 0.5%CVE-2026-19967MEDIUMOpen Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflowEPSS 0.5%CVE-2026-19970MEDIUMOpen Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 heap-based overflowEPSS 0.5%