Falhas do tipo CWE-119

3.288 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2022-28858HIGHImproper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentialEPSS 0.2%CVE-2025-14956MEDIUMWebAssembly Binaryen wasm-binary.cpp readExport heap-based overflowEPSS 0.2%CVE-2026-8088MEDIUMOSGeo gdal GDapi.c GDfieldinfo out-of-boundsEPSS 0.2%CVE-2025-9389MEDIUMvim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruptionEPSS 0.2%CVE-2025-11494MEDIUMGNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-boundsEPSS 0.2%CVE-2026-1998MEDIUMmicropython runtime.c mp_import_all memory corruptionEPSS 0.2%CVE-2023-28730HIGHA memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution EPSS 0.2%CVE-2025-0720MEDIUMMicroword eScan Antivirus Folder Watch List rtscanner removeExtraSlashes stack-based overflowEPSS 0.2%CVE-2021-29579LOWHeap buffer overflow in `MaxPoolGrad`EPSS 0.2%CVE-2022-3461HIGHBuffer Overflow in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2026-2662MEDIUMFascinatedBox lily lily_emitter.c count_transforms out-of-boundsEPSS 0.2%CVE-2022-39807—Due to lack of proper memory management, when a victim opens manipulated SolidWorks Drawing (.sldasm, CoreCadTranslator.exe) file received fEPSS 0.2%CVE-2022-34408HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2021-29576LOWHeap buffer overflow in `MaxPool3DGradGrad`EPSS 0.2%CVE-2025-9394MEDIUMPoDoFo PDF Dictionary PdfTokenizer.cpp DetermineDataType use after freeEPSS 0.2%CVE-2026-2644MEDIUMniklasso minisat DIMACS File SolverTypes.h value out-of-boundsEPSS 0.2%CVE-2021-29577LOWHeap buffer overflow in `AvgPool3DGrad`EPSS 0.2%CVE-2021-29578LOWHeap buffer overflow in `FractionalAvgPoolGrad`EPSS 0.2%CVE-2026-2659MEDIUMSquirrel sqfuncstate.cpp PopTarget out-of-boundsEPSS 0.2%CVE-2025-7323HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%