Falhas do tipo CWE-119

3.283 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-6857MEDIUMHDF5 H5Gnode.c H5G__node_cmp3 stack-based overflowEPSS 0.3%CVE-2026-12318HIGHIncorrect boundary conditions in the Libraries component in NSSEPSS 0.3%CVE-2025-3136MEDIUMPyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruptionEPSS 0.3%CVE-2023-34321LOWarm32: The cache may not be properly cleaned/invalidatedEPSS 0.3%CVE-2023-28410HIGHImproper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel versiEPSS 0.3%CVE-2025-61144CRITICALlibtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.EPSS 0.3%CVE-2026-12308MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-47169LOWImproper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of serEPSS 0.3%CVE-2026-12306MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-12307MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2025-6271MEDIUMswftools wav2swf wav.c wav_convert2mono out-of-boundsEPSS 0.3%CVE-2026-92054HIGHPrivilege escalation in the Memory componentEPSS 0.3%CVE-2025-6499MEDIUMvstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflowEPSS 0.3%CVE-2020-7261MEDIUMBuffer overwrite in ENS allowed to bypass AMSI protectionEPSS 0.3%CVE-2025-8843MEDIUMNASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflowEPSS 0.3%CVE-2024-11261MEDIUMSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruptionEPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%CVE-2023-51257HIGHAn invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.EPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%