Falhas do tipo CWE-119

3.283 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2023-48267HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2026-10703MEDIUMEIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after freeEPSS 0.2%CVE-2022-28200HIGHNVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond EPSS 0.2%CVE-2025-11277MEDIUMOpen Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflowEPSS 0.2%CVE-2025-6275MEDIUMWebAssembly wabt binary-reader-interp.cc GetFuncOffset use after freeEPSS 0.2%CVE-2025-9385MEDIUMappneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after freeEPSS 0.2%CVE-2026-96676MEDIUMFast FAC1900R uhttpd get_alias_name stack-based overflowEPSS 0.2%CVE-2025-11014MEDIUMOGRECave Ogre Image OgreSTBICodec.cpp encode heap-based overflowEPSS 0.2%CVE-2023-4949HIGHMemory Corruption Vulnerability in Grub-Legacy's XFS ImplementationEPSS 0.2%CVE-2021-36343HIGHDell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerabiliEPSS 0.2%CVE-2024-47046HIGHA vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (AlEPSS 0.2%CVE-2023-46837LOWarm32: The cache may not be properly cleaned/invalidated (take two)EPSS 0.2%CVE-2026-1418MEDIUMGPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds writeEPSS 0.2%CVE-2025-9386MEDIUMappneta tcpreplay tcprewrite get.c get_l2len_protocol use after freeEPSS 0.2%CVE-2025-3148MEDIUMcodeprojects Product Management System Login buffer overflowEPSS 0.2%CVE-2023-48368MEDIUMImproper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of servicEPSS 0.2%CVE-2025-7284HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7285HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-11495MEDIUMGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowEPSS 0.2%CVE-2023-23507HIGHThe issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2. An app may be able toEPSS 0.2%