Fallos del tipo CWE-119

3283 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-6857MEDIUMHDF5 H5Gnode.c H5G__node_cmp3 stack-based overflowEPSS 0.3%CVE-2026-16359CRITICALIncorrect boundary conditions in the Audio/Video: GMP componentEPSS 0.3%CVE-2025-3136MEDIUMPyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruptionEPSS 0.3%CVE-2023-34321LOWarm32: The cache may not be properly cleaned/invalidatedEPSS 0.3%CVE-2025-61144CRITICALlibtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.EPSS 0.3%CVE-2023-28410HIGHImproper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel versiEPSS 0.3%CVE-2026-12306MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-12307MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-12308MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-47169LOWImproper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of serEPSS 0.3%CVE-2025-6271MEDIUMswftools wav2swf wav.c wav_convert2mono out-of-boundsEPSS 0.3%CVE-2026-92054HIGHPrivilege escalation in the Memory componentEPSS 0.3%CVE-2025-6499MEDIUMvstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflowEPSS 0.3%CVE-2025-8843MEDIUMNASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflowEPSS 0.3%CVE-2020-7261MEDIUMBuffer overwrite in ENS allowed to bypass AMSI protectionEPSS 0.3%CVE-2024-11261MEDIUMSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruptionEPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2023-51257HIGHAn invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.EPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%