Fallos del tipo CWE-119

3273 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2024-38268MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versEPSS 0.4%CVE-2024-38269MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmwarEPSS 0.4%CVE-2026-8954HIGHIncorrect boundary conditions, integer overflow in the Audio/Video componentEPSS 0.4%CVE-2026-19933MEDIUMDefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflowEPSS 0.4%CVE-2024-38266MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware vEPSS 0.4%CVE-2026-4185MEDIUMGPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflowEPSS 0.4%CVE-2026-14241HIGHMemory safety bugs fixed in Firefox 152.0.4EPSS 0.4%CVE-2022-33162HIGHIBM Directory Server buffer overflowEPSS 0.4%CVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.4%CVE-2022-3545MEDIUMLinux Kernel IPsec nfp_cppcore.c area_cache_get use after freeEPSS 0.4%CVE-2026-4734CRITICALHeap Buffer Overflow in yoyofr/modizerEPSS 0.4%CVE-2025-2148LOWPyTorch Tuple torch.ops.profiler._call_end_callbacks_on_jit_fut memory corruptionEPSS 0.4%CVE-2021-3598—There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted fEPSS 0.4%CVE-2026-4738CRITICALGDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code ExecutionEPSS 0.4%CVE-2026-9637HIGHCompactLogix® 5380 / ControlLogix® 5580 - Multiple VulnerabilitiesEPSS 0.4%CVE-2022-3635MEDIUMLinux Kernel IPsec idt77252.c tst_timer use after freeEPSS 0.4%CVE-2024-11523HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11524HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11519HIGHIrfanView RLE File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11528HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%