Fallos del tipo CWE-119

3289 resultados

Corrupção de memória genérica

Fraqueza genérica que descreve quando software escreve dados fora dos limites esperados de um buffer ou estrutura de memória, sobrescrevendo dados adjacentes. Permite ao atacante corromper dados críticos, executar código arbitrário ou derrubar a aplicação.

Ejemplo

Um programa C que copia uma string do usuário para um array fixo sem validar comprimento: strcpy(buffer, user_input) em um buffer de 64 bytes, quando o input tem 200 caracteres. Os dados transbordados sobrescrevem variáveis, ponteiros ou endereços de retorno na pilha.

Cómo mitigar

Use funções seguras de cópia (strncpy, strlcpy, memcpy com tamanho validado), implemente validação de entrada e comprimento antes de qualquer operação de escrita em buffer, e ative proteções de compilador como stack canaries e ASLR. Em linguagens modernas (Rust, Go), o gerenciamento automático de memória elimina essa classe de bugs.

CVE-2026-92065HIGHSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.1%CVE-2024-21482MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in Linux Boot LoaderEPSS 0.1%CVE-2026-58005HIGHUnvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3.EPSS 0.1%CVE-2026-20731MEDIUMImproper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. UnEPSS 0.1%CVE-2026-34864MEDIUMBoundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2023-31317HIGHImproper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read orEPSS 0.1%CVE-2023-43554HIGHImproper Restriction of Operations withing the Bounds of a Memory Buffer in DSP ServicesEPSS 0.1%CVE-2025-36510MEDIUMImproper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Drivers may allow a denialEPSS 0.1%CVE-2024-43049HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2024-43053HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2024-51394MEDIUMBuffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a dEPSS 0.1%CVE-2025-62623HIGHA heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially EPSS 0.1%CVE-2023-20605MEDIUMIn keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SyEPSS 0.1%CVE-2023-21047MEDIUMIn ConvertToHalMetadata of aidl_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local infEPSS 0.1%CVE-2022-38690MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2025-20073LOWImproper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an information disclosure. SEPSS 0.1%CVE-2022-39131MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2025-20005MEDIUMImproper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System softwaEPSS 0.1%CVE-2022-42775MEDIUMIn camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2023-21044MEDIUMIn init of VendorGraphicBufferMeta, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatiEPSS 0.1%