Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2024-37676HIGHAn issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.EPSS 0.2%CVE-2025-11081MEDIUMGNU Binutils objdump.c dump_dwarf_section out-of-boundsEPSS 0.2%CVE-2025-15413MEDIUMwasm3 m3_exec.h op_CallIndirect memory corruptionEPSS 0.2%CVE-2023-25527HIGHNVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel meEPSS 0.2%CVE-2024-0429HIGHBuffer overflow vulnerability on Hex WorkshopEPSS 0.2%CVE-2026-90803MEDIUMGNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflowEPSS 0.2%CVE-2026-3282MEDIUMlibvips unpremultiply.c vips_unpremultiply_build out-of-boundsEPSS 0.2%CVE-2026-3283MEDIUMlibvips extract.c vips_extract_band_build out-of-boundsEPSS 0.2%CVE-2024-56438MEDIUMVulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.2%CVE-2026-3386MEDIUMwren-lang wren wren_compiler.c emitOp out-of-boundsEPSS 0.2%CVE-2025-12745MEDIUMQuickJS quickjs.c js_array_buffer_slice buffer over-readEPSS 0.2%CVE-2022-29279HIGHUse of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampeEPSS 0.2%CVE-2022-29275HIGHIn UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leaEPSS 0.2%CVE-2025-3000MEDIUMPyTorch torch.jit.script memory corruptionEPSS 0.2%CVE-2026-14788MEDIUMradareorg radare2 cfile.c r_core_bin_load use after freeEPSS 0.2%CVE-2026-14760MEDIUMradareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after freeEPSS 0.2%CVE-2025-2999MEDIUMPyTorch torch.nn.utils.rnn.unpack_sequence memory corruptionEPSS 0.2%CVE-2025-2998MEDIUMPyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruptionEPSS 0.2%CVE-2021-29575LOWOverflow/denial of service in `tf.raw_ops.ReverseSequence`EPSS 0.2%CVE-2025-3001MEDIUMPyTorch torch.lstm_cell memory corruptionEPSS 0.2%