Fallos del tipo CWE-119

3278 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-4501MEDIUMcode-projects Album Management System Search Albums searchalbum stack-based overflowEPSS 0.3%CVE-2024-11574HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-3565MEDIUMLinux Kernel Bluetooth l1oip_core.c del_timer use after freeEPSS 0.3%CVE-2024-12186MEDIUMcode-projects Hotel Management System Available Room hotelnew.c stack-based overflowEPSS 0.3%CVE-2024-12185MEDIUMcode-projects Hotel Management System Administrator Login Password stack-based overflowEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2026-6779MEDIUMOther issue in the JavaScript Engine componentEPSS 0.3%CVE-2026-6775MEDIUMIncorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2026-24811CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inffast.cEPSS 0.3%CVE-2025-29492MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.EPSS 0.3%CVE-2025-29496MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers tEPSS 0.3%CVE-2025-29493MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to EPSS 0.3%CVE-2025-29494MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to caEPSS 0.3%CVE-2025-1366MEDIUMMicroWord eScan Antivirus VirusPopUp strcpy stack-based overflowEPSS 0.3%CVE-2026-92032CRITICALSandbox escape due to invalid pointer in the Graphics componentEPSS 0.3%CVE-2025-15533MEDIUMraysan5 raylib rtext.c GenImageFontAtlas heap-based overflowEPSS 0.3%CVE-2022-3625MEDIUMLinux Kernel IPsec devlink.c devlink_param_get use after freeEPSS 0.3%CVE-2022-42846MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. ParsinEPSS 0.3%CVE-2025-53619HIGHAn out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DIEPSS 0.3%CVE-2022-42377HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.3%