Falhas do tipo CWE-119

3.282 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2023-2977HIGHA vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attaEPSS 0.3%CVE-2026-24798CRITICALAn Uninitialized stack variable vulnerability in GaijinEntertainment/DagorEngineEPSS 0.3%CVE-2025-53965MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480,EPSS 0.3%CVE-2022-32926MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchEPSS 0.3%CVE-2022-24419HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-3595LOWLinux Kernel CIFS sess.c sess_free_buffer double freeEPSS 0.3%CVE-2022-24420HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24415HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24421HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2022-24416HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.3%CVE-2025-6693HIGHRT-Thread device.c sys_device_write memory corruptionEPSS 0.3%CVE-2024-9731HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-29574MEDIUMBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.EPSS 0.3%CVE-2026-12317HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-29571MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of EPSS 0.3%CVE-2025-3007MEDIUMNovastar CX40 NetFilter Utility netconfig getopt stack-based overflowEPSS 0.3%CVE-2025-52264HIGHStarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.EPSS 0.3%CVE-2020-27797—An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2025-8177MEDIUMLibTIFF thumbnail.c setrow buffer overflowEPSS 0.3%CVE-2020-27798—An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%