Fallos del tipo CWE-119

3278 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-43716MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.3%CVE-2024-0774MEDIUMAny-Capture Any Sound Recorder Registration memory corruptionEPSS 0.3%CVE-2022-41211HIGHDue to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise AuEPSS 0.3%CVE-2023-1626MEDIUMJianming Antivirus IoControlCode kvcore.sys memory corruptionEPSS 0.3%CVE-2025-3728MEDIUMSourceCodester Simple Hotel Booking System login buffer overflowEPSS 0.3%CVE-2020-27796—A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2022-24939MEDIUM Malformed Zigbee packet with invalid destination address causes Assert EPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2020-3343MEDIUMCisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer VulnerabilityEPSS 0.3%CVE-2026-5475MEDIUMNASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruptionEPSS 0.3%CVE-2020-3344MEDIUMCisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer VulnerabilityEPSS 0.3%CVE-2025-13027HIGHMemory safety bugs fixed in Firefox 145 and Thunderbird 145EPSS 0.3%CVE-2025-1164MEDIUMcode-projects Police FIR Record Management System Add Record stack-based overflowEPSS 0.3%CVE-2025-11715HIGHMemory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2025-10537HIGHMemory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143EPSS 0.3%CVE-2025-3158MEDIUMOpen Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflowEPSS 0.3%CVE-2025-3159MEDIUMOpen Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflowEPSS 0.3%CVE-2024-12752HIGHFoxit PDF Reader AcroForm Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-64713MEDIUMWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodeEPSS 0.3%CVE-2020-27799—A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%