Falhas do tipo CWE-119

3.271 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-10292HIGHUTT HiPER 1200GW formTaskEdit strcpy stack-based overflowEPSS 0.5%CVE-2026-10161HIGHTRENDnet TEW-432BRP formResetStatistic stack-based overflowEPSS 0.5%CVE-2026-10122HIGHTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowEPSS 0.5%CVE-2026-10162HIGHTRENDnet TEW-432BRP formSetPassword stack-based overflowEPSS 0.5%CVE-2025-9185HIGHMemory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.5%CVE-2026-10124HIGHShibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflowEPSS 0.5%CVE-2026-82618MEDIUMSysterel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-boundsEPSS 0.5%CVE-2026-7322HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2022-1778HIGHA vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ...EPSS 0.5%CVE-2026-86514MEDIUMvgmstream txth-txtp txth.c sscanf stack-based overflowEPSS 0.5%CVE-2026-16360CRITICALMemory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153EPSS 0.5%CVE-2026-19999MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-64757HIGHA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.5%CVE-2026-12805MEDIUMOFFIS DCMTK ofxml.cc parseFile heap-based overflowEPSS 0.5%CVE-2024-22170CRITICALUnchecked buffer in Dynamic DNS clientEPSS 0.5%CVE-2025-26265MEDIUMA segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification EPSS 0.5%CVE-2026-20319HIGHCisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management VulnerabilitiesEPSS 0.5%CVE-2026-20268HIGHCisco IOS XE Software Security Hardening ReleaseEPSS 0.5%CVE-2026-11524HIGHTenda W20E Web Management modifyWifiFilterRules stack-based overflowEPSS 0.5%CVE-2026-90714MEDIUMmarcobambini Gravity JSON parser gravity_json.c memory corruptionEPSS 0.5%