Falhas do tipo CWE-119

3.283 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-3137MEDIUMCodeAstro Food Ordering System food_ordering.exe stack-based overflowEPSS 0.2%CVE-2023-23507HIGHThe issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2. An app may be able toEPSS 0.2%CVE-2024-45473HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45467HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45475HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2020-36880HIGHFlexsense DiskBoss 'Reports and Data Directory' Buffer OverflowEPSS 0.2%CVE-2023-0191HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access mayEPSS 0.2%CVE-2024-45472HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2022-41197—Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sourcesEPSS 0.2%CVE-2024-35814HIGHswiotlb: Fix double-allocation of slots due to broken alignment handlingEPSS 0.2%CVE-2019-25063MEDIUMSricam IP CCTV Camera Device Viewer memory corruptionEPSS 0.2%CVE-2024-45474HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-45468HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2025-24111MEDIUMA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOEPSS 0.2%CVE-2023-27285HIGHIBM Aspera buffer overflowEPSS 0.2%CVE-2026-92072HIGHIncorrect boundary conditions in the Safe Browsing componentEPSS 0.2%CVE-2026-12309MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.2%CVE-2025-6816MEDIUMHDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflowEPSS 0.2%CVE-2023-31364HIGHImproper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtual machine (VM) to fEPSS 0.2%CVE-2026-92178HIGHpdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%