Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-37676HIGHAn issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.EPSS 0.2%CVE-2025-15413MEDIUMwasm3 m3_exec.h op_CallIndirect memory corruptionEPSS 0.2%CVE-2025-11081MEDIUMGNU Binutils objdump.c dump_dwarf_section out-of-boundsEPSS 0.2%CVE-2023-25527HIGHNVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel meEPSS 0.2%CVE-2026-3282MEDIUMlibvips unpremultiply.c vips_unpremultiply_build out-of-boundsEPSS 0.2%CVE-2026-90803MEDIUMGNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflowEPSS 0.2%CVE-2026-3283MEDIUMlibvips extract.c vips_extract_band_build out-of-boundsEPSS 0.2%CVE-2024-0429HIGHBuffer overflow vulnerability on Hex WorkshopEPSS 0.2%CVE-2022-29275HIGHIn UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leaEPSS 0.2%CVE-2022-29279HIGHUse of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampeEPSS 0.2%CVE-2024-56438MEDIUMVulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.2%CVE-2025-12745MEDIUMQuickJS quickjs.c js_array_buffer_slice buffer over-readEPSS 0.2%CVE-2026-3386MEDIUMwren-lang wren wren_compiler.c emitOp out-of-boundsEPSS 0.2%CVE-2025-3000MEDIUMPyTorch torch.jit.script memory corruptionEPSS 0.2%CVE-2026-14760MEDIUMradareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after freeEPSS 0.2%CVE-2026-14788MEDIUMradareorg radare2 cfile.c r_core_bin_load use after freeEPSS 0.2%CVE-2025-2999MEDIUMPyTorch torch.nn.utils.rnn.unpack_sequence memory corruptionEPSS 0.2%CVE-2022-37302MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the ContEPSS 0.2%CVE-2025-2998MEDIUMPyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruptionEPSS 0.2%CVE-2025-3001MEDIUMPyTorch torch.lstm_cell memory corruptionEPSS 0.2%