Fallos del tipo CWE-119

3282 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-46301MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5203MEDIUMOpen Asset Import Library Assimp ParsingUtils.h SkipSpaces out-of-boundsEPSS 0.3%CVE-2025-46305MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5201MEDIUMOpen Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-boundsEPSS 0.3%CVE-2025-46303MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5202MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp validate_header out-of-boundsEPSS 0.3%CVE-2025-46300MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5204MEDIUMOpen Asset Import Library Assimp MDLMaterialLoader.cpp ParseSkinLump_3DGS_MDL7 out-of-boundsEPSS 0.3%CVE-2025-5200MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-boundsEPSS 0.3%CVE-2025-46302MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2024-9739HIGHTungsten Automation Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9738HIGHTungsten Automation Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9730HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-7545MEDIUMGNU Binutils objcopy.c copy_section heap-based overflowEPSS 0.3%CVE-2025-2925MEDIUMHDF5 H5MM.c H5MM_realloc double freeEPSS 0.3%CVE-2021-34856HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.3%CVE-2026-8086MEDIUMOSGeo gdal SWapi.c SWnentries heap-based overflowEPSS 0.3%CVE-2023-47580HIGHMultiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS LitEPSS 0.3%CVE-2026-16359CRITICALIncorrect boundary conditions in the Audio/Video: GMP componentEPSS 0.3%CVE-2022-32512MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code executiEPSS 0.3%