Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2021-29575LOWOverflow/denial of service in `tf.raw_ops.ReverseSequence`EPSS 0.2%CVE-2023-32436HIGHThe issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected systeEPSS 0.2%CVE-2026-14605HIGHRT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflowEPSS 0.2%CVE-2026-15506HIGHSecureAge CatchPulse Driver saappctl.sys heap-based overflowEPSS 0.2%CVE-2026-90804LOWGNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflowEPSS 0.2%CVE-2026-14606HIGHRT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflowEPSS 0.2%CVE-2022-32569HIGHImproper buffer restrictions in BIOS firmware for some Intel(R) NUC M15 Laptop Kits before version BCTGL357.0074 may allow a privileged userEPSS 0.2%CVE-2025-9136MEDIUMlibretro RetroArch file_stream.c filestream_vscanf out-of-boundsEPSS 0.2%CVE-2024-21859MEDIUMImproper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable informationEPSS 0.2%CVE-2025-6141MEDIUMGNU ncurses parse_entry.c postprocess_termcap stack-based overflowEPSS 0.2%CVE-2026-94424CRITICALMoore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflowEPSS 0.2%CVE-2022-26367MEDIUMImproper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user toEPSS 0.2%CVE-2024-31155HIGHImproper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation EPSS 0.2%CVE-2026-3391MEDIUMFascinatedBox lily lily_emitter.c clear_storages out-of-boundsEPSS 0.2%CVE-2026-3390MEDIUMFascinatedBox lily Error Reporting lily_build_error.c patch_line_end out-of-boundsEPSS 0.2%CVE-2021-26257MEDIUMImproper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 EPSS 0.2%CVE-2025-2401MEDIUMBuffer overflow in Immunity DebuggerEPSS 0.2%CVE-2022-48681HIGHSome Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions tEPSS 0.2%CVE-2026-7233MEDIUMArtifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-boundsEPSS 0.2%CVE-2025-9175MEDIUMneurobin shc shc.c make stack-based overflowEPSS 0.2%