Fallos del tipo CWE-119

3283 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-3137MEDIUMCodeAstro Food Ordering System food_ordering.exe stack-based overflowEPSS 0.2%CVE-2023-23507HIGHThe issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2. An app may be able toEPSS 0.2%CVE-2024-45472HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45475HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2022-41197—Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sourcesEPSS 0.2%CVE-2024-35814HIGHswiotlb: Fix double-allocation of slots due to broken alignment handlingEPSS 0.2%CVE-2023-0191HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access mayEPSS 0.2%CVE-2020-36880HIGHFlexsense DiskBoss 'Reports and Data Directory' Buffer OverflowEPSS 0.2%CVE-2024-45468HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2019-25063MEDIUMSricam IP CCTV Camera Device Viewer memory corruptionEPSS 0.2%CVE-2024-45474HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45467HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45473HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2023-27285HIGHIBM Aspera buffer overflowEPSS 0.2%CVE-2025-24111MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOEPSS 0.2%CVE-2026-12309MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.2%CVE-2026-92072HIGHIncorrect boundary conditions in the Safe Browsing componentEPSS 0.2%CVE-2025-6816MEDIUMHDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflowEPSS 0.2%CVE-2023-31364HIGHImproper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtual machine (VM) to fEPSS 0.2%CVE-2026-92178HIGHpdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%