Falhas do tipo CWE-119

3.282 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-6818MEDIUMHDF5 H5Ochunk.c H5O__chunk_protect heap-based overflowEPSS 0.3%CVE-2023-45168HIGHIBM AIX command executionEPSS 0.3%CVE-2025-8846MEDIUMNASM Netwide Assember parser.c parse_line stack-based overflowEPSS 0.3%CVE-2026-0139HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additionalEPSS 0.3%CVE-2025-8845MEDIUMNASM Netwide Assember nasm.c assemble_file stack-based overflowEPSS 0.3%CVE-2025-5244MEDIUMGNU Binutils ld elflink.c elf_gc_sweep memory corruptionEPSS 0.3%CVE-2026-10114MEDIUMOpen5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds writeEPSS 0.3%CVE-2021-0188HIGHReturn of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentialEPSS 0.3%CVE-2026-2016MEDIUMhappyfish100 libfastcommon base64.c base64_decode stack-based overflowEPSS 0.3%CVE-2021-0189HIGHUse of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescaEPSS 0.3%CVE-2025-14607MEDIUMOFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruptionEPSS 0.3%CVE-2025-3121MEDIUMPyTorch torch.jit.jit_module_from_flatbuffer memory corruptionEPSS 0.3%CVE-2022-32940HIGHThe issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1EPSS 0.3%CVE-2025-2923MEDIUMHDF5 H5Fint.c H5F_addr_encode_len heap-based overflowEPSS 0.3%CVE-2025-2912MEDIUMHDF5 H5Omessage.c H5O_msg_flush heap-based overflowEPSS 0.3%CVE-2020-5388MEDIUMDell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local EPSS 0.3%CVE-2022-20560HIGHProduct: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/AEPSS 0.3%CVE-2025-2914MEDIUMHDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflowEPSS 0.3%CVE-2022-32939HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An app mayEPSS 0.3%CVE-2025-9390MEDIUMvim xxd xxd.c main buffer overflowEPSS 0.3%