Falhas do tipo CWE-119

3.278 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2020-27799—A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2026-20698MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOEPSS 0.3%CVE-2025-1187MEDIUMcode-projects Police FIR Record Management System Delete Record stack-based overflowEPSS 0.3%CVE-2026-12200MEDIUMRitlabs TinyWeb Server Header libeay32.dll.html stack-based overflowEPSS 0.3%CVE-2025-6093MEDIUMuYanki board-stm32f103rc-berial heartrate1_hal.c heartrate1_i2c_hal_write stack-based overflowEPSS 0.3%CVE-2025-8040HIGHMemory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.3%CVE-2023-1679MEDIUMDriverGenius IOCTL mydrivers64.sys 0x9C40A108 memory corruptionEPSS 0.3%CVE-2025-53618HIGHAn out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DIEPSS 0.3%CVE-2026-92035CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2026-92045CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2022-28194HIGHNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker wEPSS 0.3%CVE-2026-7346HIGHInappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory acceEPSS 0.3%CVE-2022-41192—Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusteEPSS 0.3%CVE-2024-21961MEDIUMImproper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtualEPSS 0.3%CVE-2022-41188—Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untruEPSS 0.3%CVE-2023-30431HIGHIBM Db2 buffer overflowEPSS 0.3%CVE-2025-4038MEDIUMcode-projects Train Ticket Reservation System reservation stack-based overflowEPSS 0.3%CVE-2024-24921HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application is vulnerable to memory corruptEPSS 0.3%CVE-2026-12192HIGHGALAYOU Y4 Web Server buffer overflowEPSS 0.3%CVE-2025-3196MEDIUMOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflowEPSS 0.3%