Fallos del tipo CWE-119

3273 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-4719HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.4%CVE-2022-4291HIGHAswjsflt.dll in Avast Antivirus windows caused a crash of the Mozilla Firefox browser due to heap corruptionEPSS 0.4%CVE-2026-8733MEDIUMInvestintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflowEPSS 0.4%CVE-2023-37444HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-36861HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially crafted .vzt file can EPSS 0.4%CVE-2023-37442HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-38648HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A speciallyEPSS 0.4%CVE-2023-37445HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-34436HIGHAn out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 fEPSS 0.4%CVE-2023-37446HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-38649HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A speciallyEPSS 0.4%CVE-2023-38657HIGHAn out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2EPSS 0.4%CVE-2023-39443HIGHMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can EPSS 0.4%CVE-2023-37282HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A specially crafted .vzt EPSS 0.4%CVE-2023-37447HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-39444HIGHMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can EPSS 0.4%CVE-2023-37443HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2025-48429HIGHAn out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOEPSS 0.4%CVE-2026-92880MEDIUMvgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds writeEPSS 0.4%CVE-2026-8954HIGHIncorrect boundary conditions, integer overflow in the Audio/Video componentEPSS 0.4%