Falhas do tipo CWE-119

3.282 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2020-27797—An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.EPSS 0.3%CVE-2026-18291HIGHOriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-18292HIGHOriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-18294HIGHOriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-43424MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. A malicious HID deviEPSS 0.3%CVE-2025-3548MEDIUMOpen Asset Import Library Assimp File types.h Set heap-based overflowEPSS 0.3%CVE-2024-8815HIGHPDF-XChange Editor U3D File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-3549MEDIUMOpen Asset Import Library Assimp File MD3Loader.cpp ValidateSurfaceHeaderOffsets heap-based overflowEPSS 0.3%CVE-2023-45221MEDIUMImproper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilegEPSS 0.3%CVE-2021-1111MEDIUMBootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds checkEPSS 0.3%CVE-2025-10996MEDIUMOpen Babel smilesformat.cpp ParseSmiles heap-based overflowEPSS 0.3%CVE-2025-10997MEDIUMOpen Babel chemkinformat.cpp CheckSpecies heap-based overflowEPSS 0.3%CVE-2022-47967HIGHA vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability thaEPSS 0.3%CVE-2022-47935HIGHA vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versionsEPSS 0.3%CVE-2025-5245MEDIUMGNU Binutils objdump debug.c debug_type_samep memory corruptionEPSS 0.3%CVE-2025-3160MEDIUMOpen Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-boundsEPSS 0.3%CVE-2025-11840MEDIUMGNU Binutils ldmisc.c vfinfo out-of-boundsEPSS 0.3%CVE-2023-45168HIGHIBM AIX command executionEPSS 0.3%CVE-2025-8962MEDIUMcode-projects Hostel Management System Login Form hostel_manage.exe stack-based overflowEPSS 0.3%CVE-2025-6818MEDIUMHDF5 H5Ochunk.c H5O__chunk_protect heap-based overflowEPSS 0.3%