Falhas do tipo CWE-119

3.271 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-14673MEDIUMgmg137 snap7-rs client.rs as_ct_write heap-based overflowEPSS 0.5%CVE-2025-14672MEDIUMgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflowEPSS 0.5%CVE-2023-49701HIGHOut-of-bounds access a buffer in SIM managementEPSS 0.5%CVE-2025-4472MEDIUMcode-projects Departmental Store Management System bill stack-based overflowEPSS 0.5%CVE-2021-3409—The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access EPSS 0.5%CVE-2024-8389CRITICALMemory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2021-3507—A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() inEPSS 0.5%CVE-2025-5268HIGHMemory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11EPSS 0.5%CVE-2026-28935HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2023-43817HIGHDelta Electronics Delta Industrial Automation DOPSoft DPS File wMailContentLen Buffer Overflow Remote Code ExecutionEPSS 0.5%CVE-2025-2753MEDIUMOpen Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-boundsEPSS 0.5%CVE-2024-3865HIGHMemory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2023-1579HIGHHeap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.EPSS 0.5%CVE-2026-28944HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visioEPSS 0.5%CVE-2026-10259HIGHH3C Magic B0 aspForm SetMobileAPInfoById stack-based overflowEPSS 0.5%CVE-2025-4093HIGHMemory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10EPSS 0.5%CVE-2026-9365MEDIUMEttercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflowEPSS 0.5%CVE-2025-1864CRITICALBuffer Overflow and Potential Code Execution in Radare2EPSS 0.5%CVE-2026-0891HIGHMemory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2026-11413HIGHJingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflowEPSS 0.5%