Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2025-9175MEDIUMneurobin shc shc.c make stack-based overflowEPSS 0.2%CVE-2025-15538MEDIUMOpen Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after freeEPSS 0.2%CVE-2026-3663MEDIUMxlnt-community xlnt XLSX File compound_document.cpp xsgetn out-of-boundsEPSS 0.2%CVE-2023-25509MEDIUMNVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.EPSS 0.2%CVE-2026-2258MEDIUMaardappel lobster wfc.h WaveFunctionCollapse memory corruptionEPSS 0.2%CVE-2026-9541MEDIUMSquirrel Cnut File sqobject.cpp ReadObject heap-based overflowEPSS 0.2%CVE-2023-49699MEDIUMOut-of-bounds access a buffer in IMSEPSS 0.2%CVE-2025-14419HIGHpdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-2858MEDIUMwren-lang wren Source File wren_compiler.c peekChar out-of-boundsEPSS 0.2%CVE-2022-42286MEDIUMDGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.EPSS 0.2%CVE-2026-3606MEDIUMEttercap etterfilter ef_output.c add_data_segment out-of-boundsEPSS 0.2%CVE-2024-33658MEDIUMBuffer Overflow Vulnerability In OFBDEPSS 0.2%CVE-2026-3664MEDIUMxlnt-community xlnt Encrypted XLSX File compound_document.cpp read_directory out-of-boundsEPSS 0.2%CVE-2025-3017MEDIUMTA-Lib ta_regtest test_minmax.c setInputBuffer out-of-bounds writeEPSS 0.2%CVE-2023-28383MEDIUMImproper conditions check in some Intel(R) BIOS PPAM firmware may allow a privileged user to potentially enable escalation of privilege via EPSS 0.2%CVE-2026-20024MEDIUMA vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacEPSS 0.2%CVE-2025-3144MEDIUMMindSpore mindspore.numpy.fft.hfftn memory corruptionEPSS 0.2%CVE-2024-0645HIGHBuffer Overflow Vulnerability in Explorer++EPSS 0.2%CVE-2026-15520MEDIUMGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2025-3145MEDIUMMindSpore mindspore.numpy.fft.rfft2 memory corruptionEPSS 0.2%