Falhas do tipo CWE-119

3.278 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-11574HIGHIrfanView DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-4501MEDIUMcode-projects Album Management System Search Albums searchalbum stack-based overflowEPSS 0.3%CVE-2022-3565MEDIUMLinux Kernel Bluetooth l1oip_core.c del_timer use after freeEPSS 0.3%CVE-2024-12186MEDIUMcode-projects Hotel Management System Available Room hotelnew.c stack-based overflowEPSS 0.3%CVE-2024-12185MEDIUMcode-projects Hotel Management System Administrator Login Password stack-based overflowEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2026-6779MEDIUMOther issue in the JavaScript Engine componentEPSS 0.3%CVE-2026-6775MEDIUMIncorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2025-29496MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers tEPSS 0.3%CVE-2026-24811CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inffast.cEPSS 0.3%CVE-2025-29492MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.EPSS 0.3%CVE-2025-29493MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to EPSS 0.3%CVE-2026-92032CRITICALSandbox escape due to invalid pointer in the Graphics componentEPSS 0.3%CVE-2025-29494MEDIUMlibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to caEPSS 0.3%CVE-2025-1366MEDIUMMicroWord eScan Antivirus VirusPopUp strcpy stack-based overflowEPSS 0.3%CVE-2022-3625MEDIUMLinux Kernel IPsec devlink.c devlink_param_get use after freeEPSS 0.3%CVE-2025-15533MEDIUMraysan5 raylib rtext.c GenImageFontAtlas heap-based overflowEPSS 0.3%CVE-2025-53619HIGHAn out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DIEPSS 0.3%CVE-2022-42846MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. ParsinEPSS 0.3%CVE-2026-43716MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.3%