Falhas do tipo CWE-119

3.278 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2022-25662MEDIUMInformation disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdEPSS 0.4%CVE-2023-1676HIGHDriverGenius IOCTL mydrivers64.sys 0x9C402088 memory corruptionEPSS 0.4%CVE-2025-0529MEDIUMcode-projects Train Ticket Reservation System Login Form stack-based overflowEPSS 0.4%CVE-2026-76756MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2026-76755MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2024-12354MEDIUMSourceCodester Phone Contact Manager System User Menu MenuDisplayStart buffer overflowEPSS 0.4%CVE-2026-76757MEDIUMGammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100EPSS 0.4%CVE-2022-42809HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted gcx file maEPSS 0.4%CVE-2022-3541MEDIUMLinux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after freeEPSS 0.4%CVE-2022-3715HIGHA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory proEPSS 0.4%CVE-2022-0500—A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF EPSS 0.4%CVE-2025-2309MEDIUMHDF5 Type Conversion Logic H5T__bit_copy heap-based overflowEPSS 0.4%CVE-2026-33444MEDIUMMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2026-55398MEDIUMMemory management vulnerability in Secure Access clientsEPSS 0.4%CVE-2025-29485MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to causeEPSS 0.4%CVE-2026-52188MEDIUMBuffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the goheaEPSS 0.4%CVE-2022-3636MEDIUMLinux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after freeEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2020-8230—A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed toEPSS 0.4%CVE-2025-4029MEDIUMcode-projects Personal Diary Management System New Record addrecord stack-based overflowEPSS 0.4%