Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2022-26124HIGHImproper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R)EPSS 0.2%CVE-2025-0050MEDIUMMali GPU Userspace Driver allows an Out-of-Bounds accessEPSS 0.2%CVE-2026-12330MEDIUMIncorrect boundary conditions in the Internationalization componentEPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2025-8736MEDIUMGNU cflow Lexer c.c yylex buffer overflowEPSS 0.2%CVE-2026-1979MEDIUMmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after freeEPSS 0.2%CVE-2025-12771HIGHIBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buffer.EPSS 0.2%CVE-2023-0202HIGHNVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacEPSS 0.2%CVE-2023-0206HIGHNVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A succEPSS 0.2%CVE-2026-33847HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in linkingvision rapidvmsEPSS 0.2%CVE-2026-2246MEDIUMAprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruptionEPSS 0.2%CVE-2026-90826LOWGPAC MP4Box base_scenegraph.c gf_node_del out-of-boundsEPSS 0.2%CVE-2026-9504MEDIUMGNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-boundsEPSS 0.2%CVE-2026-91088LOWGPAC URL url.c gf_url_concatenate_ex heap-based overflowEPSS 0.2%CVE-2024-44238HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be ableEPSS 0.2%CVE-2026-17512MEDIUMggml-org whisper.cpp log_mel_spectrogram out-of-boundsEPSS 0.2%CVE-2026-4012MEDIUMrxi fe fe.c read_ out-of-boundsEPSS 0.2%CVE-2026-15194MEDIUMOpen5GS AMF context.c amf_context_final use after freeEPSS 0.2%CVE-2022-32491MEDIUMDell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability bEPSS 0.2%CVE-2026-4010MEDIUMThakeeNathees pocketlang pkByteBufferAddString memory corruptionEPSS 0.2%