Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-4015MEDIUMGPAC TeXML File load_text.c txtin_process_texml stack-based overflowEPSS 0.2%CVE-2022-34417HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-19206MEDIUMMZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadless heap-based overflowEPSS 0.2%CVE-2022-34423HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-90682MEDIUMMatthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflowEPSS 0.2%CVE-2022-34420HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-9500MEDIUMGNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflowEPSS 0.2%CVE-2022-34416HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34411HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34418HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34406HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34413HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-3994MEDIUMrui314 mold Object File input-files.cc initialize_sections heap-based overflowEPSS 0.2%CVE-2022-34422HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34410HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34407HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34414HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-6491MEDIUMlibvips nip2 vips7compat.c im_minpos_vec heap-based overflowEPSS 0.2%CVE-2022-34409HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-9502MEDIUMGNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflowEPSS 0.2%