Fallos del tipo CWE-119

3276 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-39872MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and EPSS 0.4%CVE-2026-43663MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and EPSS 0.4%CVE-2024-10559MEDIUMSourceCodester Airport Booking Management System details buffer overflowEPSS 0.4%CVE-2026-16368CRITICALIncorrect boundary conditions in the JavaScript: WebAssembly componentEPSS 0.4%CVE-2020-3545MEDIUMCisco FXOS Software Buffer Overflow VulnerabilityEPSS 0.4%CVE-2021-3582—A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" coEPSS 0.4%CVE-2020-3423MEDIUMCisco IOS XE Software Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2025-31263CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor EPSS 0.4%CVE-2023-36747HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specEPSS 0.4%CVE-2024-26335MEDIUMswftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.EPSS 0.4%CVE-2026-87489HIGHMemory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sEPSS 0.4%CVE-2026-6767MEDIUMOther issue in the Libraries component in NSSEPSS 0.4%CVE-2026-43707MEDIUMA memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, mEPSS 0.4%CVE-2026-82479MEDIUMNASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflowEPSS 0.4%CVE-2020-27801—A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.4%CVE-2026-28913HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.4%CVE-2022-42844HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of iEPSS 0.4%CVE-2026-15105MEDIUMdavenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds writeEPSS 0.4%CVE-2025-43419HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visiEPSS 0.4%CVE-2025-46298MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS EPSS 0.4%