Fallos del tipo CWE-119

3277 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-6516MEDIUMHDF5 H5Fint.c H5F_addr_decode_len heap-based overflowEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2025-3166MEDIUMcode-projects Product Management System Search Product Menu search_item stack-based overflowEPSS 0.4%CVE-2025-4077MEDIUMcode-projects School Billing System searchrec stack-based overflowEPSS 0.4%CVE-2025-4069MEDIUMcode-projects Product Management System add_item stack-based overflowEPSS 0.4%CVE-2025-3763MEDIUMSourceCodester Phone Management System Password main buffer overflowEPSS 0.4%CVE-2026-12305HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2025-4059MEDIUMcode-projects Prison Management System Prison_Mgmt_Sys addrecord stack-based overflowEPSS 0.4%CVE-2023-42841HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPEPSS 0.4%CVE-2025-4068MEDIUMcode-projects Simple Movie Ticket Booking System changeprize stack-based overflowEPSS 0.4%CVE-2025-4471MEDIUMcode-projects Jewelery Store Management system Search Item View stack-based overflowEPSS 0.4%CVE-2023-36746HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specEPSS 0.4%CVE-2022-41180—Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2022-39808—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%CVE-2026-12222HIGHYealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflowEPSS 0.4%CVE-2026-12220HIGHYealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflowEPSS 0.4%CVE-2026-12221HIGHYealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflowEPSS 0.4%CVE-2026-43740MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.4%CVE-2026-12218HIGHYealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflowEPSS 0.4%