Falhas do tipo CWE-119

3.273 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-39870HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. PEPSS 0.4%CVE-2025-14333HIGHMemory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146EPSS 0.4%CVE-2026-10066HIGHShibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflowEPSS 0.4%CVE-2026-10065HIGHShibby Tomato tomatodata.cgi get_ups_field stack-based overflowEPSS 0.4%CVE-2026-10067HIGHShibby Tomato multimon.cgi sub_90F0 stack-based overflowEPSS 0.4%CVE-2024-10498MEDIUMCWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacEPSS 0.4%CVE-2026-14383HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2025-2357MEDIUMDCMTK dcmjpls JPEG-LS Decoder memory corruptionEPSS 0.4%CVE-2026-14407HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2023-35955HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35958HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35970HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-35956HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2021-1308HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-1251HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2025-1866CRITICALUndefined Behavior Due to Out-of-Bounds Pointer Arithmetic in libwebsocketsEPSS 0.4%CVE-2023-42047HIGHPDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-3812MEDIUMQEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_EPSS 0.4%CVE-2025-1368MEDIUMMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflowEPSS 0.4%CVE-2026-4719HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.4%