Falhas do tipo CWE-119

3.283 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2020-7261MEDIUMBuffer overwrite in ENS allowed to bypass AMSI protectionEPSS 0.3%CVE-2025-6120MEDIUMOpen Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflowEPSS 0.3%CVE-2024-11261MEDIUMSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruptionEPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2023-51257HIGHAn invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.EPSS 0.3%CVE-2025-15536MEDIUMBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflowEPSS 0.3%CVE-2024-13941MEDIUMouch-org ouch zip.rs convert_zip_date_time memory corruptionEPSS 0.3%CVE-2026-92071CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.3%CVE-2024-23133HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.3%CVE-2025-6269MEDIUMHDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflowEPSS 0.3%CVE-2026-8087MEDIUMOSGeo gdal GDapi.c GDnentries heap-based overflowEPSS 0.3%CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2025-6270MEDIUMHDF5 H5FSsection.c H5FS__sect_find_node heap-based overflowEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2025-14861HIGHMemory safety bugs fixed in Firefox 146.0.1EPSS 0.3%CVE-2022-41173—Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sEPSS 0.3%CVE-2022-41171—Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusEPSS 0.3%CVE-2022-41182—Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTranslator.exe) file receEPSS 0.3%CVE-2026-64788MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27,EPSS 0.3%CVE-2022-41169—Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrEPSS 0.3%