Fallos del tipo CWE-119

3288 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-8556LOWInappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2026-2660MEDIUMFascinatedBox lily lily_symtab.c shorthash_for_name use after freeEPSS 0.2%CVE-2025-3588MEDIUMjoelittlejohn jsonschema2pojo JSON File SchemaRule.java apply stack-based overflowEPSS 0.2%CVE-2022-22558MEDIUMDell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification EPSS 0.2%CVE-2023-49618HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2025-8961MEDIUMLibTIFF tiffcrop tiffcrop.c main memory corruptionEPSS 0.2%CVE-2022-41183—Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted soEPSS 0.2%CVE-2025-11412MEDIUMGNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-boundsEPSS 0.2%CVE-2025-7244HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-41174—Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrustEPSS 0.2%CVE-2022-41176—Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sourEPSS 0.2%CVE-2022-41181—Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received frEPSS 0.2%CVE-2025-7243HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-8001HIGHAshlar-Vellum Cobalt CO File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7246HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-11414MEDIUMGNU Binutils Linker elflink.c get_link_hash_entry out-of-boundsEPSS 0.2%CVE-2021-41289MEDIUMASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory BufferEPSS 0.2%CVE-2026-2913LOWlibvips source.c vips_source_read_to_memory heap-based overflowEPSS 0.2%CVE-2026-3394MEDIUMjarikomppa soloud WAV File soloud_wav.cpp loadwav memory corruptionEPSS 0.2%CVE-2025-11081MEDIUMGNU Binutils objdump.c dump_dwarf_section out-of-boundsEPSS 0.2%