Falhas do tipo CWE-119

3.288 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-7254HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7278HIGHIrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7249HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7239HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-81581HIGHUser input in WibuKey is used (without proper sanitization) to compute the address of a pointer, which can be exploited to let the user point to any storage, to which Windows responds with a denial of service.EPSS 0.2%CVE-2026-3463MEDIUMxlnt-community xlnt Compound Document binary.hpp append heap-based overflowEPSS 0.2%CVE-2023-25755HIGHScreen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory EPSS 0.2%CVE-2022-46781LOWAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to accesEPSS 0.2%CVE-2025-3791MEDIUMsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflowEPSS 0.2%CVE-2024-0153HIGHMali GPU Firmware allows improper GPU processing operationsEPSS 0.2%CVE-2025-8746MEDIUMGNU libopts __strstr_sse2 memory corruptionEPSS 0.2%CVE-2023-33124HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2026-3285MEDIUMberry-lang berry be_lexer.c scan_string out-of-boundsEPSS 0.2%CVE-2026-2657MEDIUMwren-lang wren Error Message wren_compiler.c printError stack-based overflowEPSS 0.2%CVE-2025-15537MEDIUMMapnik dbfile.cpp string_value heap-based overflowEPSS 0.2%CVE-2025-8585MEDIUMlibav DSS File Demuxer avconv.c main double freeEPSS 0.2%CVE-2022-23523MEDIUMrust-vmm linux-loader vulnerable to Out-of-bounds ReadEPSS 0.2%CVE-2026-28984MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.2%CVE-2022-34488HIGHImproper buffer restrictions in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentiaEPSS 0.2%CVE-2021-33847HIGHImproper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 EPSS 0.2%