Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2022-34407HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-90682MEDIUMMatthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflowEPSS 0.2%CVE-2022-34410HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34416HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2024-4162MEDIUMKW Watcher Vulnerability ALlows Malicious Read Access to MemoryEPSS 0.2%CVE-2026-9502MEDIUMGNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2022-34420HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34414HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-4015MEDIUMGPAC TeXML File load_text.c txtin_process_texml stack-based overflowEPSS 0.2%CVE-2022-34421HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34413HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-9500MEDIUMGNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflowEPSS 0.2%CVE-2022-34418HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2022-34419HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-18784MEDIUMo6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflowEPSS 0.2%CVE-2026-3994MEDIUMrui314 mold Object File input-files.cc initialize_sections heap-based overflowEPSS 0.2%CVE-2022-34406HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%CVE-2026-82591MEDIUMOpen Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflowEPSS 0.2%CVE-2026-19206MEDIUMMZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadless heap-based overflowEPSS 0.2%CVE-2022-34422HIGH Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious userEPSS 0.2%