Falhas do tipo CWE-119

3.283 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-5165MEDIUMOpen Asset Import Library Assimp MDCLoader.cpp ValidateSurfaceHeader out-of-boundsEPSS 0.2%CVE-2021-3635—A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able EPSS 0.2%CVE-2025-9300MEDIUMsaitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflowEPSS 0.2%CVE-2022-48662HIGHdrm/i915/gem: Really move i915_gem_context.link under ref protectionEPSS 0.2%CVE-2025-15150MEDIUMPX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflowEPSS 0.2%CVE-2024-44067HIGHThe T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivilegedEPSS 0.2%CVE-2020-36855MEDIUMDCMTK dcmqrscp parseQuota stack-based overflowEPSS 0.2%CVE-2026-10194MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflowEPSS 0.2%CVE-2025-11683MEDIUMYAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Read and potential Information DisclosureEPSS 0.2%CVE-2021-22705—Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthoriEPSS 0.2%CVE-2025-2913MEDIUMHDF5 H5FL.c H5FL__blk_gc_list use after freeEPSS 0.2%CVE-2025-5648LOWRadare2 radiff2 pal.c r_cons_pal_init memory corruptionEPSS 0.2%CVE-2026-25634HIGHiccDEV memcpy-param-overlap in CIccTagMultiProcessElement::Apply()EPSS 0.2%CVE-2025-11275MEDIUMOpen Asset Import Library Assimp OpenDDLParserUtils.h getNextSeparator heap-based overflowEPSS 0.2%CVE-2025-6750MEDIUMHDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflowEPSS 0.2%CVE-2025-10994MEDIUMOpen Babel gamessformat.cpp ReadMolecule use after freeEPSS 0.2%CVE-2025-3139MEDIUMcode-projects Bus Reservation System Login Form login buffer overflowEPSS 0.2%CVE-2026-65341MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and EPSS 0.2%CVE-2023-48267HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2022-26045LOWImproper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user toEPSS 0.2%