Fallos del tipo CWE-119

3276 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-10064MEDIUMTRENDnet TEW-432BRP formSetPortTr stack-based overflowEPSS 0.4%CVE-2026-9299MEDIUMomec-project amf handler.go PDUSessionResourceModifyIndication memory corruptionEPSS 0.4%CVE-2026-78157MEDIUMOpen5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-boundsEPSS 0.4%CVE-2026-16225MEDIUMdavenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds writeEPSS 0.4%CVE-2026-14604MEDIUMOpen Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double freeEPSS 0.4%CVE-2026-9300MEDIUMomec-project amf NGSetupRequest memory corruptionEPSS 0.4%CVE-2025-15685MEDIUMOpen5GS freeDiameter memory corruptionEPSS 0.4%CVE-2026-9301MEDIUMomec-project amf NGReset Message memory corruptionEPSS 0.4%CVE-2026-9298MEDIUMomec-project amf PathSwitchRequest memory corruptionEPSS 0.4%CVE-2025-2310MEDIUMHDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflowEPSS 0.4%CVE-2023-50187HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42036HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-12290HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2023-34087HIGHAn improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .eEPSS 0.4%CVE-2024-45809MEDIUMJwt filter crash in the clear route cache with remote JWKs in envoyEPSS 0.4%CVE-2024-9684HIGHFreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific message sequences.EPSS 0.4%CVE-2022-41185—Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received fEPSS 0.4%CVE-2026-6764MEDIUMIncorrect boundary conditions in the DOM: Device Interfaces componentEPSS 0.4%CVE-2026-20636MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visioEPSS 0.4%CVE-2026-1145MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_constructor_ta heap-based overflowEPSS 0.4%