Fallos del tipo CWE-119

3279 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-34988LOWWasmtime leaks data between pooling allocator instancesEPSS 0.3%CVE-2025-5297MEDIUMSourceCodester Computer Store System main.c Add stack-based overflowEPSS 0.3%CVE-2026-10701HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.3%CVE-2025-58750HIGHrAthena missing bound check in chclif_parse_moveCharSlotEPSS 0.3%CVE-2024-33258HIGHJerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.EPSS 0.3%CVE-2026-16393CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.3%CVE-2025-2849MEDIUMUPX p_lx_elf.cpp un_DT_INIT heap-based overflowEPSS 0.3%CVE-2026-1110MEDIUMcijliu librtsp rtsp_parse_method buffer overflowEPSS 0.3%CVE-2025-2915MEDIUMHDF5 H5Faccum.c H5F__accum_free heap-based overflowEPSS 0.3%CVE-2025-2924MEDIUMHDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflowEPSS 0.3%CVE-2025-12204MEDIUMKamailio Configuration File rvalue.c rve_destroy heap-based overflowEPSS 0.3%CVE-2023-37332HIGHKofax Power PDF PNG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-0251HIGHCVE-2023-0251EPSS 0.3%CVE-2023-37333HIGHKofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-30775MEDIUMA vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.cEPSS 0.3%CVE-2026-10275LOWOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflowEPSS 0.3%CVE-2025-43277HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.EPSS 0.3%CVE-2026-92048CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.3%CVE-2022-2947HIGH Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory locatEPSS 0.3%CVE-2025-53965MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480,EPSS 0.3%