Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-90610MEDIUMGPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-readEPSS 0.2%CVE-2025-55159MEDIUMslab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds checkEPSS 0.2%CVE-2026-84566HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2026-90825MEDIUMGPAC MP4Box base_scenegraph.c gf_node_unregister use after freeEPSS 0.2%CVE-2026-90827MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-92473MEDIUMGPAC BIFS commands.c gf_sg_command_del use after freeEPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-90831MEDIUMGNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruptionEPSS 0.2%CVE-2022-20570MEDIUMProduct: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/AEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2026-2240MEDIUMjanet-lang janet compile.c janetc_pop_funcdef out-of-boundsEPSS 0.2%CVE-2022-34391HIGHDell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated maliciouEPSS 0.2%CVE-2022-34377LOW Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious usEPSS 0.2%CVE-2026-2242MEDIUMjanet-lang janet specials.c janetc_if out-of-boundsEPSS 0.2%CVE-2026-2655LOWChaiScript chaiscript_defines.hpp operator use after freeEPSS 0.2%CVE-2026-2656LOWChaiScript type_info.hpp bare_equal use after freeEPSS 0.2%CVE-2026-14607MEDIUMRT-Thread lwp_syscall.c sys_getaddrinfo memory corruptionEPSS 0.2%CVE-2025-23397HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2022-26124HIGHImproper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R)EPSS 0.2%