Falhas do tipo CWE-119

3.278 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-43716MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.EPSS 0.3%CVE-2022-41211HIGHDue to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise AuEPSS 0.3%CVE-2023-1626MEDIUMJianming Antivirus IoControlCode kvcore.sys memory corruptionEPSS 0.3%CVE-2024-0774MEDIUMAny-Capture Any Sound Recorder Registration memory corruptionEPSS 0.3%CVE-2020-27796—A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2022-24939MEDIUM Malformed Zigbee packet with invalid destination address causes Assert EPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2025-3728MEDIUMSourceCodester Simple Hotel Booking System login buffer overflowEPSS 0.3%CVE-2020-3344MEDIUMCisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer VulnerabilityEPSS 0.3%CVE-2020-3343MEDIUMCisco AMP for Endpoints Linux Connector and AMP for Endpoints Mac Connector Software Memory Buffer VulnerabilityEPSS 0.3%CVE-2026-5475MEDIUMNASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruptionEPSS 0.3%CVE-2025-13027HIGHMemory safety bugs fixed in Firefox 145 and Thunderbird 145EPSS 0.3%CVE-2025-1164MEDIUMcode-projects Police FIR Record Management System Add Record stack-based overflowEPSS 0.3%CVE-2025-3158MEDIUMOpen Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflowEPSS 0.3%CVE-2025-11715HIGHMemory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2025-3159MEDIUMOpen Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflowEPSS 0.3%CVE-2025-10537HIGHMemory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143EPSS 0.3%CVE-2024-12752HIGHFoxit PDF Reader AcroForm Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-64713MEDIUMWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodeEPSS 0.3%CVE-2020-27799—A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%