Falhas do tipo CWE-119

3.272 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-0892CRITICALMemory safety bugs fixed in Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2026-20156HIGHCisco RoomOS Security Hardening Release - Buffer Management VulnerabilitiesEPSS 0.5%CVE-2026-6753HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-6752HIGHIncorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-8389HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2026-7323HIGHMemory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1EPSS 0.5%CVE-2025-2755MEDIUMOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-boundsEPSS 0.5%CVE-2026-8973HIGHMemory safety bugs fixed in Firefox 151EPSS 0.5%CVE-2022-38692CRITICALIn BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without rEPSS 0.5%CVE-2023-3471HIGHBuffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.5%CVE-2026-43795MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2026-65335MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65338MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.5%CVE-2022-0367—A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.EPSS 0.5%CVE-2026-65334MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10EPSS 0.5%CVE-2026-65330MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe EPSS 0.5%CVE-2026-100740CRITICALD-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds writeEPSS 0.5%CVE-2025-0753MEDIUMAxiomatic Bento4 mp42aac ReadPartial heap-based overflowEPSS 0.5%CVE-2018-0342—A vulnerability in the configuration and monitoring service of the Cisco SD-WAN Solution could allow an authenticated, local attacker to exeEPSS 0.5%CVE-2026-19970MEDIUMOpen Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 heap-based overflowEPSS 0.5%