Fallos del tipo CWE-119

3278 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2023-1676HIGHDriverGenius IOCTL mydrivers64.sys 0x9C402088 memory corruptionEPSS 0.4%CVE-2022-25662MEDIUMInformation disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdEPSS 0.4%CVE-2026-76757MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2024-12354MEDIUMSourceCodester Phone Contact Manager System User Menu MenuDisplayStart buffer overflowEPSS 0.4%CVE-2026-76756MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2026-76755MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2022-42809HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted gcx file maEPSS 0.4%CVE-2022-3541MEDIUMLinux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after freeEPSS 0.4%CVE-2022-3715HIGHA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory proEPSS 0.4%CVE-2022-0500—A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF EPSS 0.4%CVE-2025-2309MEDIUMHDF5 Type Conversion Logic H5T__bit_copy heap-based overflowEPSS 0.4%CVE-2025-29485MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to causeEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2026-52188MEDIUMBuffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the goheaEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2022-3636MEDIUMLinux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after freeEPSS 0.4%CVE-2020-8230—A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed toEPSS 0.4%CVE-2025-4892MEDIUMcode-projects Police Station Management System Delete Record source.cpp remove stack-based overflowEPSS 0.4%