Falhas do tipo CWE-119

3.276 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2023-50187HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-9298MEDIUMomec-project amf PathSwitchRequest memory corruptionEPSS 0.4%CVE-2026-16225MEDIUMdavenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds writeEPSS 0.4%CVE-2025-10225HIGHIncorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One (C-Werk)EPSS 0.4%CVE-2026-14604MEDIUMOpen Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double freeEPSS 0.4%CVE-2026-10064MEDIUMTRENDnet TEW-432BRP formSetPortTr stack-based overflowEPSS 0.4%CVE-2026-78157MEDIUMOpen5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-boundsEPSS 0.4%CVE-2025-15685MEDIUMOpen5GS freeDiameter memory corruptionEPSS 0.4%CVE-2026-9299MEDIUMomec-project amf handler.go PDUSessionResourceModifyIndication memory corruptionEPSS 0.4%CVE-2025-2310MEDIUMHDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflowEPSS 0.4%CVE-2026-9300MEDIUMomec-project amf NGSetupRequest memory corruptionEPSS 0.4%CVE-2023-42036HIGHKofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-12290HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2023-34087HIGHAn improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .eEPSS 0.4%CVE-2026-20636MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visioEPSS 0.4%CVE-2024-9684HIGHFreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific message sequences.EPSS 0.4%CVE-2024-45809MEDIUMJwt filter crash in the clear route cache with remote JWKs in envoyEPSS 0.4%CVE-2026-1145MEDIUMquickjs-ng quickjs quickjs.c js_typed_array_constructor_ta heap-based overflowEPSS 0.4%CVE-2022-41185—Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received fEPSS 0.4%CVE-2026-6764MEDIUMIncorrect boundary conditions in the DOM: Device Interfaces componentEPSS 0.4%