Falhas do tipo CWE-119

3.273 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2018-0342—A vulnerability in the configuration and monitoring service of the Cisco SD-WAN Solution could allow an authenticated, local attacker to exeEPSS 0.5%CVE-2025-9187CRITICALMemory safety bugs fixed in Firefox 142 and Thunderbird 142EPSS 0.4%CVE-2026-8959CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.4%CVE-2026-8974HIGHMemory safety bugs fixed in Firefox ESR 140.11 and Firefox 151EPSS 0.4%CVE-2018-1068—A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrEPSS 0.4%CVE-2019-25078MEDIUMpacparser pacparser.c pacparser_find_proxy buffer overflowEPSS 0.4%CVE-2024-23257LOWThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS SonEPSS 0.4%CVE-2026-10125HIGHEdimax BR-6478AC POST Request formPPPoESetup stack-based overflowEPSS 0.4%CVE-2024-21980HIGHImproper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMCEPSS 0.4%CVE-2026-10121HIGHTRENDnet TEW-432BRP formSetUrlFilter stack-based overflowEPSS 0.4%CVE-2024-9403HIGHMemory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.4%CVE-2023-42043HIGHPDF-XChange Editor PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-15247MEDIUMgmg137 snap7-rs client.rs download heap-based overflowEPSS 0.4%CVE-2024-20011CRITICALIn alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with EPSS 0.4%CVE-2023-31194MEDIUMAn improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markEPSS 0.4%CVE-2025-8044CRITICALMemory safety bugs fixed in Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2025-2521HIGHLack of indexes’ validation against buffer borders leads to remote code execution.EPSS 0.4%CVE-2025-26597HIGHXorg: xwayland: buffer overflow in xkbchangetypesofkey()EPSS 0.4%CVE-2025-60016HIGHBIG-IP SSL/TLS vulnerabilityEPSS 0.4%CVE-2023-31355MEDIUMImproper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially alloEPSS 0.4%