Fallos del tipo CWE-119

3278 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-20698MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOEPSS 0.3%CVE-2020-27800—A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2025-1187MEDIUMcode-projects Police FIR Record Management System Delete Record stack-based overflowEPSS 0.3%CVE-2026-12200MEDIUMRitlabs TinyWeb Server Header libeay32.dll.html stack-based overflowEPSS 0.3%CVE-2025-8040HIGHMemory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.3%CVE-2023-1679MEDIUMDriverGenius IOCTL mydrivers64.sys 0x9C40A108 memory corruptionEPSS 0.3%CVE-2025-6093MEDIUMuYanki board-stm32f103rc-berial heartrate1_hal.c heartrate1_i2c_hal_write stack-based overflowEPSS 0.3%CVE-2026-92035CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2025-53618HIGHAn out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DIEPSS 0.3%CVE-2026-92045CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2024-21961MEDIUMImproper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtualEPSS 0.3%CVE-2026-7346HIGHInappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory acceEPSS 0.3%CVE-2022-28194HIGHNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker wEPSS 0.3%CVE-2022-41192—Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusteEPSS 0.3%CVE-2022-41188—Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untruEPSS 0.3%CVE-2023-30431HIGHIBM Db2 buffer overflowEPSS 0.3%CVE-2024-24921HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application is vulnerable to memory corruptEPSS 0.3%CVE-2025-4038MEDIUMcode-projects Train Ticket Reservation System reservation stack-based overflowEPSS 0.3%CVE-2026-12192HIGHGALAYOU Y4 Web Server buffer overflowEPSS 0.3%CVE-2025-3196MEDIUMOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflowEPSS 0.3%