Fallos del tipo CWE-119

3283 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2023-48267HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2022-28200HIGHNVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond EPSS 0.2%CVE-2025-6275MEDIUMWebAssembly wabt binary-reader-interp.cc GetFuncOffset use after freeEPSS 0.2%CVE-2026-10703MEDIUMEIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after freeEPSS 0.2%CVE-2025-11277MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflowEPSS 0.2%CVE-2025-9385MEDIUMappneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after freeEPSS 0.2%CVE-2026-96676MEDIUMFast FAC1900R uhttpd get_alias_name stack-based overflowEPSS 0.2%CVE-2023-4949HIGHMemory Corruption Vulnerability in Grub-Legacy's XFS ImplementationEPSS 0.2%CVE-2026-1418MEDIUMGPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds writeEPSS 0.2%CVE-2023-46837LOWarm32: The cache may not be properly cleaned/invalidated (take two)EPSS 0.2%CVE-2024-47046HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2025-11014MEDIUMOGRECave Ogre Image OgreSTBICodec.cpp encode heap-based overflowEPSS 0.2%CVE-2021-36343HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2025-9386MEDIUMappneta tcpreplay tcprewrite get.c get_l2len_protocol use after freeEPSS 0.2%CVE-2025-3148MEDIUMcodeprojects Product Management System Login buffer overflowEPSS 0.2%CVE-2023-48368MEDIUMImproper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of servicEPSS 0.2%CVE-2025-7284HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7285HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-11495MEDIUMGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowEPSS 0.2%CVE-2026-3137MEDIUMCodeAstro Food Ordering System food_ordering.exe stack-based overflowEPSS 0.2%