Falhas do tipo CWE-119

3.277 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-6516MEDIUMHDF5 H5Fint.c H5F_addr_decode_len heap-based overflowEPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%CVE-2023-42841HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPEPSS 0.4%CVE-2025-4069MEDIUMcode-projects Product Management System add_item stack-based overflowEPSS 0.4%CVE-2025-3763MEDIUMSourceCodester Phone Management System Password main buffer overflowEPSS 0.4%CVE-2026-12305HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2025-4059MEDIUMcode-projects Prison Management System Prison_Mgmt_Sys addrecord stack-based overflowEPSS 0.4%CVE-2025-3166MEDIUMcode-projects Product Management System Search Product Menu search_item stack-based overflowEPSS 0.4%CVE-2025-4068MEDIUMcode-projects Simple Movie Ticket Booking System changeprize stack-based overflowEPSS 0.4%CVE-2025-4077MEDIUMcode-projects School Billing System searchrec stack-based overflowEPSS 0.4%CVE-2022-41180—Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2025-4471MEDIUMcode-projects Jewelery Store Management system Search Item View stack-based overflowEPSS 0.4%CVE-2023-36746HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specEPSS 0.4%CVE-2022-39808—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%CVE-2026-12220HIGHYealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflowEPSS 0.4%CVE-2026-12218HIGHYealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflowEPSS 0.4%CVE-2026-43740MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.4%CVE-2026-12221HIGHYealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflowEPSS 0.4%CVE-2026-12222HIGHYealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflowEPSS 0.4%