Falhas do tipo CWE-119

3.276 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-11564HIGHIrfanView DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-16350CRITICALIncorrect boundary conditions in the Audio/Video: cubeb componentEPSS 0.4%CVE-2026-16357CRITICALIncorrect boundary conditions in the Graphics componentEPSS 0.4%CVE-2025-2851HIGHGL.iNet GL-A1300 Slate Plus RPC plugins.so buffer overflowEPSS 0.4%CVE-2021-0242MEDIUMJunos OS: EX4300: FPC crash upon receipt of specific frames on an interface without L2PT or dot1x configuredEPSS 0.4%CVE-2025-8034HIGHMemory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2025-33077HIGHIBM Engineering Systems Design Rhapsody code executionEPSS 0.4%CVE-2020-8896MEDIUMBuffer Overflow in Google Earth ProEPSS 0.4%CVE-2026-20352HIGHCisco Identity Services Engine RADIUS Denial of Service VulnerabilityEPSS 0.4%CVE-2021-1521MEDIUMCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.4%CVE-2025-2308MEDIUMHDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflowEPSS 0.4%CVE-2024-11522HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38082HIGHKofax Power PDF GIF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38084HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-43264HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image mayEPSS 0.4%CVE-2024-11538HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-23129HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2025-21483CRITICALImproper Restriction of Operations within the Bounds of a Memory Buffer in Data Network Stack & ConnectivityEPSS 0.4%CVE-2024-52923HIGHAn issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 128EPSS 0.4%CVE-2026-9299MEDIUMomec-project amf handler.go PDUSessionResourceModifyIndication memory corruptionEPSS 0.4%