Falhas do tipo CWE-119

3.274 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2022-3161HIGH The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execuEPSS 0.4%CVE-2024-11262MEDIUMSourceCodester Student Record Management System View All Student Marks main stack-based overflowEPSS 0.4%CVE-2023-43816MEDIUMDelta Electronics Delta Industrial Automation DOPSoft DPS File wKPFStringLen Buffer Overflow Remote Code ExecutionEPSS 0.4%CVE-2026-10904HIGHInappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2017-15128—A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cauEPSS 0.4%CVE-2026-3697MEDIUMPlanet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflowEPSS 0.4%CVE-2024-5306HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-1144MEDIUMquickjs-ng quickjs Atomics Ops quickjs.c use after freeEPSS 0.4%CVE-2026-4710CRITICALIncorrect boundary conditions in the Audio/Video componentEPSS 0.4%CVE-2026-33848HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in linkingvision rapidvmsEPSS 0.4%CVE-2026-33849HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in linkingvision rapidvmsEPSS 0.4%CVE-2026-82608MEDIUMKamailio AVP cxdx_avp.c get_4bytes out-of-boundsEPSS 0.4%CVE-2026-19955MEDIUMTrailDB TOC Validation tdb.c tdb_open out-of-boundsEPSS 0.4%CVE-2025-7616MEDIUMgmg137 snap7-rs Public API pthread_cond_destroy memory corruptionEPSS 0.4%CVE-2023-42037HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-41186—Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from uEPSS 0.4%CVE-2026-12327HIGHMemory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152EPSS 0.4%CVE-2024-11553HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11564HIGHIrfanView DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-1425MEDIUMpymumu SmartDNS SVBC Record dns.c _dns_decode_SVCB_HTTPS stack-based overflowEPSS 0.4%