Falhas do tipo CWE-119

3.273 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-4719HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.4%CVE-2019-3812MEDIUMQEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_EPSS 0.4%CVE-2023-37443HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-37442HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-34436HIGHAn out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 fEPSS 0.4%CVE-2023-37446HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-36861HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially crafted .vzt file can EPSS 0.4%CVE-2023-38648HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A speciallyEPSS 0.4%CVE-2023-37445HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-39444HIGHMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can EPSS 0.4%CVE-2023-37447HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-38657HIGHAn out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2EPSS 0.4%CVE-2023-39443HIGHMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can EPSS 0.4%CVE-2023-37282HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A specially crafted .vzt EPSS 0.4%CVE-2023-37444HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2026-8733MEDIUMInvestintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflowEPSS 0.4%CVE-2025-48429HIGHAn out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOEPSS 0.4%CVE-2023-38649HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A speciallyEPSS 0.4%CVE-2026-92880MEDIUMvgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds writeEPSS 0.4%CVE-2026-19933MEDIUMDefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflowEPSS 0.4%