Falhas do tipo CWE-119

3.279 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-34988LOWWasmtime leaks data between pooling allocator instancesEPSS 0.3%CVE-2025-5297MEDIUMSourceCodester Computer Store System main.c Add stack-based overflowEPSS 0.3%CVE-2026-10701HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.3%CVE-2024-33258HIGHJerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.EPSS 0.3%CVE-2025-58750HIGHrAthena missing bound check in chclif_parse_moveCharSlotEPSS 0.3%CVE-2026-16393CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-1110MEDIUMcijliu librtsp rtsp_parse_method buffer overflowEPSS 0.3%CVE-2025-2849MEDIUMUPX p_lx_elf.cpp un_DT_INIT heap-based overflowEPSS 0.3%CVE-2025-2915MEDIUMHDF5 H5Faccum.c H5F__accum_free heap-based overflowEPSS 0.3%CVE-2025-12204MEDIUMKamailio Configuration File rvalue.c rve_destroy heap-based overflowEPSS 0.3%CVE-2025-2924MEDIUMHDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflowEPSS 0.3%CVE-2023-37332HIGHKofax Power PDF PNG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-0251HIGHCVE-2023-0251EPSS 0.3%CVE-2026-10275LOWOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflowEPSS 0.3%CVE-2023-37333HIGHKofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-30775MEDIUMA vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.cEPSS 0.3%CVE-2026-92048CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.3%CVE-2025-43277HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.EPSS 0.3%CVE-2022-2947HIGH Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory locatEPSS 0.3%CVE-2023-2977HIGHA vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attaEPSS 0.3%