Fallos del tipo CWE-119

3277 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-11516MEDIUMUTT HiPER 2610G formNatStaticMap strcpy buffer overflowEPSS 0.4%CVE-2026-84145HIGHInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2025-62594MEDIUMImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)EPSS 0.4%CVE-2019-10142HIGHA flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parametEPSS 0.4%CVE-2025-1364MEDIUMMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflowEPSS 0.4%CVE-2025-0412HIGHLuxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2025-9184HIGHMemory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.4%CVE-2025-4480MEDIUMcode-projects Simple College Management System Add New Student input stack-based overflowEPSS 0.4%CVE-2020-36881HIGHFlexsense DiskBoss 'Add Input Directory' Buffer OverflowEPSS 0.4%CVE-2025-4497MEDIUMcode-projects Simple Banking System Sign In buffer overflowEPSS 0.4%CVE-2025-11721CRITICALMemory safety bug fixed in Firefox 144 and Thunderbird 144EPSS 0.4%CVE-2026-28941HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. PEPSS 0.4%CVE-2026-90716MEDIUMmarcobambini Gravity Number gravity_parser.c parse_number_expression out-of-boundsEPSS 0.4%CVE-2026-7324HIGHMemory safety bugs fixed in Thunderbird 150.0.1EPSS 0.4%CVE-2024-0772MEDIUMNsasoft ShareAlarmPro Registration memory corruptionEPSS 0.4%CVE-2025-52566HIGHllama.cpp tokenizer signed vs. unsigned heap overflowEPSS 0.4%CVE-2025-1367MEDIUMMicroWord eScan Antivirus USB Password sprintf buffer overflowEPSS 0.4%CVE-2023-2873MEDIUMTwister Antivirus IoControlCode filppd.sys 0x80800043 memory corruptionEPSS 0.4%CVE-2026-12326HIGHMemory safety bugs fixed in Firefox 152 and Thunderbird 152EPSS 0.4%