Falhas do tipo CWE-119

3.271 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-90714MEDIUMmarcobambini Gravity JSON parser gravity_json.c memory corruptionEPSS 0.5%CVE-2026-11524HIGHTenda W20E Web Management modifyWifiFilterRules stack-based overflowEPSS 0.5%CVE-2026-11528HIGHTenda AC18 Web Management getRebootStatus sub_45304 stack-based overflowEPSS 0.5%CVE-2026-11503HIGHTenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflowEPSS 0.5%CVE-2026-11523HIGHTenda W20E Web Management PortalAuth formPortalAuth stack-based overflowEPSS 0.5%CVE-2024-0338HIGHBuffer Overflow Vulnerability in XAMPPEPSS 0.5%CVE-2026-0822MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_sort heap-based overflowEPSS 0.5%CVE-2026-8388MEDIUMIncorrect boundary conditions in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2022-1270HIGHIn GraphicsMagick, a heap buffer overflow was found when parsing MIFF.EPSS 0.5%CVE-2026-10158HIGHTRENDnet TEW-432BRP formPortFw stack-based overflowEPSS 0.5%CVE-2026-10120HIGHTRENDnet TEW-432BRP formSetFirewallRule stack-based overflowEPSS 0.5%CVE-2026-10164HIGHEdimax BR-6478AC POST Request formUSBFolder buffer overflowEPSS 0.5%CVE-2026-10159HIGHTRENDnet TEW-432BRP formSysLog stack-based overflowEPSS 0.5%CVE-2026-10163HIGHEdimax BR-6478AC POST Request formUSBAccount buffer overflowEPSS 0.5%CVE-2020-27792HIGHGhostscript: heap buffer over write vulnerability in ghostscript's lp8000_print_page() in gdevlp8k.cEPSS 0.5%CVE-2026-5733HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.5%CVE-2021-3611—A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash thEPSS 0.5%CVE-2024-32761MEDIUMBIG-IP TMM tenants on VELOS and rSeries vulnerabilityEPSS 0.5%CVE-2020-17397HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must firEPSS 0.5%CVE-2025-43373HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. AEPSS 0.5%