Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-84537MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2025-23398HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2025-23400HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2026-6776HIGHIncorrect boundary conditions in the WebRTC: Networking componentEPSS 0.2%CVE-2023-28587HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in BT ControllerEPSS 0.2%CVE-2026-5186MEDIUMNothings stb Multi-frame GIF File stb_image.h stbi__load_gif_main double freeEPSS 0.2%CVE-2025-9020LOWPX4 PX4-Autopilot Mavlink Shell Closing mavlink_receiver.cpp handle_message_serial_control use after freeEPSS 0.2%CVE-2023-41779MEDIUMIllegal Memory Access Vulnerability of ZTE's ZXCLOUD iRAIEPSS 0.2%CVE-2026-22167HIGHGPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryEPSS 0.2%CVE-2025-1246HIGHMali GPU Userspace Driver allows an Out-of-Bounds accessEPSS 0.2%CVE-2024-33016MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in StorageEPSS 0.2%CVE-2024-36434HIGHAn SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.EPSS 0.2%CVE-2024-36433HIGHAn arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware beforEPSS 0.2%CVE-2025-20053HIGHImproper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enableEPSS 0.2%CVE-2024-0162MEDIUMDell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local lowEPSS 0.2%CVE-2026-36910MEDIUMAn access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial oEPSS 0.2%CVE-2026-43767MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.1%CVE-2025-33044MEDIUMexFat Memory Corruption IssueEPSS 0.1%CVE-2025-58409LOWGPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes corrupting memoryEPSS 0.1%CVE-2025-15013MEDIUMfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflowEPSS 0.1%