Falhas do tipo CWE-119

3.282 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-9390MEDIUMvim xxd xxd.c main buffer overflowEPSS 0.3%CVE-2025-5203MEDIUMOpen Asset Import Library Assimp ParsingUtils.h SkipSpaces out-of-boundsEPSS 0.3%CVE-2025-46305MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5201MEDIUMOpen Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-boundsEPSS 0.3%CVE-2025-46303MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5202MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp validate_header out-of-boundsEPSS 0.3%CVE-2025-46300MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2025-5204MEDIUMOpen Asset Import Library Assimp MDLMaterialLoader.cpp ParseSkinLump_3DGS_MDL7 out-of-boundsEPSS 0.3%CVE-2025-5200MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-boundsEPSS 0.3%CVE-2025-46302MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS SeEPSS 0.3%CVE-2024-9738HIGHTungsten Automation Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9730HIGHTrimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-7545MEDIUMGNU Binutils objcopy.c copy_section heap-based overflowEPSS 0.3%CVE-2024-9739HIGHTungsten Automation Power PDF PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2925MEDIUMHDF5 H5MM.c H5MM_realloc double freeEPSS 0.3%CVE-2021-34856HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.3%CVE-2026-8086MEDIUMOSGeo gdal SWapi.c SWnentries heap-based overflowEPSS 0.3%CVE-2023-47580HIGHMultiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS LitEPSS 0.3%CVE-2022-32512MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code executiEPSS 0.3%CVE-2025-6857MEDIUMHDF5 H5Gnode.c H5G__node_cmp3 stack-based overflowEPSS 0.3%