Fallos del tipo CWE-119

3282 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-24798CRITICALAn Uninitialized stack variable vulnerability in GaijinEntertainment/DagorEngineEPSS 0.3%CVE-2026-24794CRITICALChunk Unloading Security Vulnerability in CardboardPowered/cardboardEPSS 0.3%CVE-2023-2977HIGHA vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attaEPSS 0.3%CVE-2025-53965MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480,EPSS 0.3%CVE-2022-24420HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24419HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-3595LOWLinux Kernel CIFS sess.c sess_free_buffer double freeEPSS 0.3%CVE-2022-24421HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24416HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24415HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2025-6693HIGHRT-Thread device.c sys_device_write memory corruptionEPSS 0.3%CVE-2024-9731HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-29574MEDIUMBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.EPSS 0.3%CVE-2026-12317HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-29571MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of EPSS 0.3%CVE-2025-52264HIGHStarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.EPSS 0.3%CVE-2025-3007MEDIUMNovastar CX40 NetFilter Utility netconfig getopt stack-based overflowEPSS 0.3%CVE-2025-8177MEDIUMLibTIFF thumbnail.c setrow buffer overflowEPSS 0.3%CVE-2020-27798—An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2020-27797—An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%