Fallos del tipo CWE-119

3283 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-6499MEDIUMvstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflowEPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2024-11261MEDIUMSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruptionEPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%CVE-2023-51257HIGHAn invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.EPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2026-92071CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.3%CVE-2025-6270MEDIUMHDF5 H5FSsection.c H5FS__sect_find_node heap-based overflowEPSS 0.3%CVE-2026-8087MEDIUMOSGeo gdal GDapi.c GDnentries heap-based overflowEPSS 0.3%CVE-2025-6269MEDIUMHDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflowEPSS 0.3%CVE-2024-23133HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2024-13941MEDIUMouch-org ouch zip.rs convert_zip_date_time memory corruptionEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2025-14861HIGHMemory safety bugs fixed in Firefox 146.0.1EPSS 0.3%CVE-2026-64788MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27,EPSS 0.3%CVE-2022-41171—Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusEPSS 0.3%CVE-2022-41166—Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untruEPSS 0.3%CVE-2022-41173—Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sEPSS 0.3%CVE-2022-41169—Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrEPSS 0.3%