Falhas do tipo CWE-119

3.271 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-10189HIGHTenda W12 httpd cgiSysTimeInfoSet stack-based overflowEPSS 0.5%CVE-2026-10192HIGHTenda W12 httpd set_local_time_0 stack-based overflowEPSS 0.5%CVE-2026-28940HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS EPSS 0.5%CVE-2023-44184MEDIUMJunos OS and Junos OS Evolved: High CPU load due to specific NETCONF commandEPSS 0.5%CVE-2023-28581CRITICALImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN FirmwareEPSS 0.5%CVE-2026-19969MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-10206HIGHD-Link DI-8400 dbsrv.asp stack-based overflowEPSS 0.5%CVE-2025-2584LOWWebAssembly wabt binary-reader-interp.cc GetReturnCallDropKeepCount heap-based overflowEPSS 0.5%CVE-2026-28911CRITICALThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be EPSS 0.5%CVE-2021-1131MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.5%CVE-2025-4091HIGHMemory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10EPSS 0.5%CVE-2026-7668MEDIUMMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-boundsEPSS 0.5%CVE-2026-0886MEDIUMIncorrect boundary conditions in the Graphics componentEPSS 0.5%CVE-2022-32455HIGHTMM vulnerability CVE-2022-32455EPSS 0.5%CVE-2025-0751MEDIUMAxiomatic Bento4 mp42aac ReadBits heap-based overflowEPSS 0.5%CVE-2026-16411CRITICALMemory safety bugs fixed in Firefox 153EPSS 0.5%CVE-2026-12292HIGHIncorrect boundary conditions in the Web Audio componentEPSS 0.5%CVE-2025-14672MEDIUMgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflowEPSS 0.5%CVE-2022-3213—A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavEPSS 0.5%CVE-2025-14673MEDIUMgmg137 snap7-rs client.rs as_ct_write heap-based overflowEPSS 0.5%