Falhas do tipo CWE-119

3.273 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-38268MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versEPSS 0.4%CVE-2024-38269MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmwarEPSS 0.4%CVE-2026-8954HIGHIncorrect boundary conditions, integer overflow in the Audio/Video componentEPSS 0.4%CVE-2026-19933MEDIUMDefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflowEPSS 0.4%CVE-2024-38266MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware vEPSS 0.4%CVE-2026-4185MEDIUMGPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflowEPSS 0.4%CVE-2026-14241HIGHMemory safety bugs fixed in Firefox 152.0.4EPSS 0.4%CVE-2022-33162HIGHIBM Directory Server buffer overflowEPSS 0.4%CVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.4%CVE-2022-3545MEDIUMLinux Kernel IPsec nfp_cppcore.c area_cache_get use after freeEPSS 0.4%CVE-2026-4734CRITICALHeap Buffer Overflow in yoyofr/modizerEPSS 0.4%CVE-2025-2148LOWPyTorch Tuple torch.ops.profiler._call_end_callbacks_on_jit_fut memory corruptionEPSS 0.4%CVE-2021-3598—There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted fEPSS 0.4%CVE-2026-4738CRITICALGDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code ExecutionEPSS 0.4%CVE-2026-9637HIGHCompactLogix® 5380 / ControlLogix® 5580 - Multiple VulnerabilitiesEPSS 0.4%CVE-2022-3635MEDIUMLinux Kernel IPsec idt77252.c tst_timer use after freeEPSS 0.4%CVE-2024-11523HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11524HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11519HIGHIrfanView RLE File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11528HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%