Falhas do tipo CWE-119

3.277 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-11516MEDIUMUTT HiPER 2610G formNatStaticMap strcpy buffer overflowEPSS 0.4%CVE-2026-84145HIGHInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2025-62594MEDIUMImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)EPSS 0.4%CVE-2019-10142HIGHA flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parametEPSS 0.4%CVE-2025-1364MEDIUMMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflowEPSS 0.4%CVE-2025-9184HIGHMemory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142EPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2025-0412HIGHLuxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.4%CVE-2020-36881HIGHFlexsense DiskBoss 'Add Input Directory' Buffer OverflowEPSS 0.4%CVE-2025-4497MEDIUMcode-projects Simple Banking System Sign In buffer overflowEPSS 0.4%CVE-2025-4480MEDIUMcode-projects Simple College Management System Add New Student input stack-based overflowEPSS 0.4%CVE-2025-11721CRITICALMemory safety bug fixed in Firefox 144 and Thunderbird 144EPSS 0.4%CVE-2026-28941HIGHThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. PEPSS 0.4%CVE-2026-7324HIGHMemory safety bugs fixed in Thunderbird 150.0.1EPSS 0.4%CVE-2026-90716MEDIUMmarcobambini Gravity Number gravity_parser.c parse_number_expression out-of-boundsEPSS 0.4%CVE-2024-0772MEDIUMNsasoft ShareAlarmPro Registration memory corruptionEPSS 0.4%CVE-2025-1367MEDIUMMicroWord eScan Antivirus USB Password sprintf buffer overflowEPSS 0.4%CVE-2026-12326HIGHMemory safety bugs fixed in Firefox 152 and Thunderbird 152EPSS 0.4%CVE-2025-52566HIGHllama.cpp tokenizer signed vs. unsigned heap overflowEPSS 0.4%CVE-2023-2873MEDIUMTwister Antivirus IoControlCode filppd.sys 0x80800043 memory corruptionEPSS 0.4%