Falhas do tipo CWE-119

3.288 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-8545LOWObject corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer processEPSS 0.2%CVE-2026-2660MEDIUMFascinatedBox lily lily_symtab.c shorthash_for_name use after freeEPSS 0.2%CVE-2026-8556LOWInappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2023-49618HIGHImproper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to poEPSS 0.2%CVE-2025-8961MEDIUMLibTIFF tiffcrop tiffcrop.c main memory corruptionEPSS 0.2%CVE-2022-41183—Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted soEPSS 0.2%CVE-2022-22558MEDIUMDell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification EPSS 0.2%CVE-2025-7244HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7246HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-11414MEDIUMGNU Binutils Linker elflink.c get_link_hash_entry out-of-boundsEPSS 0.2%CVE-2022-41181—Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received frEPSS 0.2%CVE-2022-41176—Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sourEPSS 0.2%CVE-2025-11412MEDIUMGNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-boundsEPSS 0.2%CVE-2022-41174—Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrustEPSS 0.2%CVE-2025-7243HIGHIrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-8001HIGHAshlar-Vellum Cobalt CO File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2021-41289MEDIUMASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory BufferEPSS 0.2%CVE-2026-2913LOWlibvips source.c vips_source_read_to_memory heap-based overflowEPSS 0.2%CVE-2026-3394MEDIUMjarikomppa soloud WAV File soloud_wav.cpp loadwav memory corruptionEPSS 0.2%CVE-2025-15413MEDIUMwasm3 m3_exec.h op_CallIndirect memory corruptionEPSS 0.2%