Falhas do tipo CWE-119

3.270 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-13522MEDIUMInvestintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-boundsEPSS 0.5%CVE-2023-30774—A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROEPSS 0.5%CVE-2026-18585MEDIUMGL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflowEPSS 0.5%CVE-2026-28955HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28902MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2026-28901MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2024-22041HIGHA vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions),EPSS 0.5%CVE-2019-1771HIGHCisco Webex Network Recording Player Arbitrary Code Execution VulnerabilityEPSS 0.5%CVE-2025-2756MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflowEPSS 0.5%CVE-2026-28847HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28903MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2022-3628MEDIUMA buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious UEPSS 0.5%CVE-2025-14330CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2024-9400HIGHA potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during EPSS 0.5%CVE-2024-14043MEDIUMOpen5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflowEPSS 0.5%CVE-2024-14044MEDIUMOpen5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflowEPSS 0.5%CVE-2022-23813MEDIUMThe software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest meEPSS 0.5%CVE-2025-3015MEDIUMOpen Asset Import Library Assimp ASE File ASELoader.cpp BuildUniqueRepresentation out-of-boundsEPSS 0.5%CVE-2026-0821MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_constructor heap-based overflowEPSS 0.5%CVE-2024-14042MEDIUMOpen5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflowEPSS 0.5%