Falhas do tipo CWE-119

3.271 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-1163MEDIUMcode-projects Vehicle Parking Management System Authentication login stack-based overflowEPSS 0.5%CVE-2022-25310—A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c EPSS 0.5%CVE-2025-2750MEDIUMOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds writeEPSS 0.5%CVE-2022-20602HIGHProduct: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/AEPSS 0.5%CVE-2022-20601HIGHProduct: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/AEPSS 0.5%CVE-2026-11553HIGHTenda HG7HG9/HG10 formPPPEdit stack-based overflowEPSS 0.5%CVE-2026-11557HIGHTenda F451 Web Management Natlimit fromNatlimit stack-based overflowEPSS 0.5%CVE-2026-10188HIGHTenda W12 httpd cgistaKickOff stack-based overflowEPSS 0.5%CVE-2026-10191HIGHTenda W12 httpd cgiWifiMacFilterSet stack-based overflowEPSS 0.5%CVE-2026-0878HIGHSandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2022-0496—A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-oEPSS 0.5%CVE-2025-3407MEDIUMNothings stb stbhw_build_tileset_from_image out-of-boundsEPSS 0.5%CVE-2026-10165HIGHEdimax BR-6478AC POST Request formWanTcpipSetup stack-based overflowEPSS 0.5%CVE-2026-10119HIGHTRENDnet TEW-432BRP formSetMACFilter stack-based overflowEPSS 0.5%CVE-2026-10123HIGHTRENDnet TEW-432BRP formSetDomainFilter stack-based overflowEPSS 0.5%CVE-2025-9185HIGHMemory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.5%CVE-2026-10183HIGHTRENDnet TEW-432BRP formWlanSetup stack-based overflowEPSS 0.5%CVE-2026-10293HIGHUTT HiPER 1200GW formFireWall strcpy stack-based overflowEPSS 0.5%CVE-2026-10161HIGHTRENDnet TEW-432BRP formResetStatistic stack-based overflowEPSS 0.5%CVE-2026-10292HIGHUTT HiPER 1200GW formTaskEdit strcpy stack-based overflowEPSS 0.5%