Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2025-13566MEDIUMjarun nnn nnn.c run_cmd_as_plugin double freeEPSS 0.1%CVE-2026-2069MEDIUMggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflowEPSS 0.1%CVE-2023-52548HIGHHuawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leEPSS 0.1%CVE-2025-21096LOWImproper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilegeEPSS 0.1%CVE-2026-10230MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflowEPSS 0.1%CVE-2022-25681HIGHPossible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caEPSS 0.1%CVE-2022-25682HIGHMemory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon CEPSS 0.1%CVE-2022-25661HIGHMemory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdragonEPSS 0.1%CVE-2023-31351MEDIUMImproper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integEPSS 0.1%CVE-2026-10229MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.1%CVE-2026-10200MEDIUMAssimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflowEPSS 0.1%CVE-2025-9338HIGHA improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered byEPSS 0.1%CVE-2026-10528MEDIUMOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflowEPSS 0.1%CVE-2026-11623LOWtmux image.c image_free use after freeEPSS 0.1%CVE-2025-36156HIGHIBM InfoSphere Data Replication VSAM for z/OS Remote Source code executionEPSS 0.1%CVE-2022-33210HIGHMemory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large EPSS 0.1%CVE-2026-10231MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflowEPSS 0.1%CVE-2026-92059CRITICALIncorrect boundary conditions in the DOM: Editor componentEPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2024-23369HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%