Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-28896HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.8, macOS Sonoma 1EPSS 0.2%CVE-2026-15520MEDIUMGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2025-43398MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS EPSS 0.2%CVE-2025-15506MEDIUMAcademySoftwareFoundation OpenColorIO FileRules.cpp ConvertToRegularExpression out-of-boundsEPSS 0.2%CVE-2023-3889HIGHMali GPU Kernel Driver exposes sensitive data from freed memoryEPSS 0.2%CVE-2023-3953MEDIUM A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption EPSS 0.2%CVE-2023-6361HIGHA vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlEPSS 0.2%CVE-2023-6362HIGHA vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlEPSS 0.2%CVE-2025-6490MEDIUMsparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflowEPSS 0.2%CVE-2026-94128CRITICALBioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-whereEPSS 0.2%CVE-2026-94129CRITICALBioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-whereEPSS 0.2%CVE-2026-94142CRITICALBioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-whereEPSS 0.2%CVE-2025-7546MEDIUMGNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds writeEPSS 0.2%CVE-2026-94146CRITICALBioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-whereEPSS 0.2%CVE-2024-23980HIGHImproper buffer restrictions in PlatformPfrDxe driver in UEFI firmware for some Intel(R) Server D50FCP Family products may allow a privilegeEPSS 0.2%CVE-2026-90824MEDIUMGPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflowEPSS 0.2%CVE-2025-11947LOWbftpd Configuration File options.c expand_groups heap-based overflowEPSS 0.2%CVE-2022-20599MEDIUMIn Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of prEPSS 0.2%CVE-2024-1174HIGHPrevious versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP has released HP ThinPrEPSS 0.2%CVE-2025-46333HIGHz2d OOB composition could lead to invalid memory access and corruptionEPSS 0.2%