Falhas do tipo CWE-119

3.273 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2023-1629MEDIUMJiangMin Antivirus IOCTL kvcore.sys 0x222010 memory corruptionEPSS 0.4%CVE-2026-84144HIGHInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2EPSS 0.4%CVE-2024-11519HIGHIrfanView RLE File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-7464MEDIUMosrg GoBGP rtr.go SplitRTR out-of-boundsEPSS 0.4%CVE-2026-43794HIGHA memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10,EPSS 0.4%CVE-2026-90815MEDIUMFFmpeg Convolution Filter vf_convolution.c setup_3x3 out-of-boundsEPSS 0.4%CVE-2026-21634MEDIUMA malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery prEPSS 0.4%CVE-2024-27344HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-8093HIGHMemory safety bugs fixed in Firefox 150.0.2EPSS 0.4%CVE-2026-90572MEDIUMdavenardella snap7 s7_micro_client.cpp opUpload memory corruptionEPSS 0.4%CVE-2025-33076HIGHIBM Engineering Systems Design Rhapsody code executionEPSS 0.4%CVE-2023-35957HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35969HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-39486HIGHPDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-4390MEDIUMTeamSpeak 3 Server Connection State Management process_resend_queue use after freeEPSS 0.4%CVE-2025-52582HIGHAn out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafEPSS 0.4%CVE-2021-3674HIGHA flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted valEPSS 0.4%CVE-2022-3161HIGH The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execuEPSS 0.4%CVE-2020-27787—A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalidEPSS 0.4%CVE-2026-87444HIGHMemory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vEPSS 0.4%