Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2023-28550HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in MPP PerformanceEPSS 0.1%CVE-2023-28551HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in UTILSEPSS 0.1%CVE-2026-92076HIGHIncorrect boundary conditions in the Networking componentEPSS 0.1%CVE-2023-21628HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN HALEPSS 0.1%CVE-2022-25713HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in AutomotiveEPSS 0.1%CVE-2023-28549HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN HALEPSS 0.1%CVE-2023-21633MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21637MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in LinuxEPSS 0.1%CVE-2023-21663MEDIUMImproper Restrictions of Operations within the Bounds of a Memory Buffer in DisplayEPSS 0.1%CVE-2022-33267MEDIUMImproper restriction of operations within the bounds of memory buffer in LinuxEPSS 0.1%CVE-2026-10232MEDIUMAssimp ASE File scene.cpp ~aiNode use after freeEPSS 0.1%CVE-2023-21654MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in AudioEPSS 0.1%CVE-2024-21481HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HypervisorEPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2026-10233MEDIUMAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-boundsEPSS 0.1%CVE-2026-12216MEDIUMsvaarala duktape duk_api_bytecode.c memory corruptionEPSS 0.1%CVE-2021-25518MEDIUMAn improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2024-23356HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%CVE-2026-92065HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%CVE-2026-92064HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%