Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-15013MEDIUMfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflowEPSS 0.1%CVE-2025-9157MEDIUMappneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after freeEPSS 0.1%CVE-2025-33195MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A succeEPSS 0.1%CVE-2025-13120MEDIUMmruby array.c sort_cmp use after freeEPSS 0.1%CVE-2025-11015MEDIUMOGRECave Ogre OgreSTBICodec.cpp encode mismatched memory management routinesEPSS 0.1%CVE-2024-11495HIGHBuffer overflow in OllyDbgEPSS 0.1%CVE-2025-10824MEDIUMaxboe fio init.c __parse_jobs_ini use after freeEPSS 0.1%CVE-2026-12193HIGHVS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflowEPSS 0.1%CVE-2022-34376LOW Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may EPSS 0.1%CVE-2025-22885MEDIUMImproper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a priviEPSS 0.1%CVE-2023-28545HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in TZ Secure OSEPSS 0.1%CVE-2023-21634MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in Radio Interface LayerEPSS 0.1%CVE-2026-20621MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS EPSS 0.1%CVE-2026-1465HIGHA heap-based buffer over-read or buffer overflow in tildearrow/furnaceEPSS 0.1%CVE-2025-55286HIGHz2d OOB drawing with new multi-sample anti-aliasing could lead to invalid memory access and corruptionEPSS 0.1%CVE-2023-28586MEDIUMImproper Restriction of Operation within the Bounds of a Memory Buffer in TZ Secure OSEPSS 0.1%CVE-2025-14569MEDIUMggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeEPSS 0.1%CVE-2026-30883MEDIUMImageMagick has a Heap Overflow when writing extremely large image profile in the PNG encoderEPSS 0.1%CVE-2026-2245MEDIUMCCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-boundsEPSS 0.1%CVE-2026-20654MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOEPSS 0.1%