Fallos del tipo CWE-119

3288 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-7254HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7278HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7249HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7239HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-81581HIGHUser input in WibuKey is used (without proper sanitization) to compute the address of a pointer, which can be exploited to let the user point to any storage, to which Windows responds with a denial of service.EPSS 0.2%CVE-2026-3463MEDIUMxlnt-community xlnt Compound Document binary.hpp append heap-based overflowEPSS 0.2%CVE-2023-25755HIGHScreen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory EPSS 0.2%CVE-2022-46781LOWAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to accesEPSS 0.2%CVE-2025-3791MEDIUMsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflowEPSS 0.2%CVE-2024-0153HIGHMali GPU Firmware allows improper GPU processing operationsEPSS 0.2%CVE-2025-8746MEDIUMGNU libopts __strstr_sse2 memory corruptionEPSS 0.2%CVE-2023-33124HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2026-3285MEDIUMberry-lang berry be_lexer.c scan_string out-of-boundsEPSS 0.2%CVE-2026-2657MEDIUMwren-lang wren Error Message wren_compiler.c printError stack-based overflowEPSS 0.2%CVE-2025-15537MEDIUMMapnik dbfile.cpp string_value heap-based overflowEPSS 0.2%CVE-2025-8585MEDIUMlibav DSS File Demuxer avconv.c main double freeEPSS 0.2%CVE-2022-23523MEDIUMrust-vmm linux-loader vulnerable to Out-of-bounds ReadEPSS 0.2%CVE-2026-28984MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.2%CVE-2022-34488HIGHImproper buffer restrictions in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentiaEPSS 0.2%CVE-2021-33847HIGHImproper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 EPSS 0.2%