Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2026-90610MEDIUMGPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-readEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2022-20570MEDIUMProduct: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/AEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2025-55159MEDIUMslab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds checkEPSS 0.2%CVE-2026-90825MEDIUMGPAC MP4Box base_scenegraph.c gf_node_unregister use after freeEPSS 0.2%CVE-2026-84566HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2026-90827MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-92473MEDIUMGPAC BIFS commands.c gf_sg_command_del use after freeEPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%CVE-2026-90831MEDIUMGNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruptionEPSS 0.2%CVE-2026-2242MEDIUMjanet-lang janet specials.c janetc_if out-of-boundsEPSS 0.2%CVE-2022-34377LOW Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious usEPSS 0.2%CVE-2026-2656LOWChaiScript type_info.hpp bare_equal use after freeEPSS 0.2%CVE-2026-14607MEDIUMRT-Thread lwp_syscall.c sys_getaddrinfo memory corruptionEPSS 0.2%CVE-2026-2240MEDIUMjanet-lang janet compile.c janetc_pop_funcdef out-of-boundsEPSS 0.2%CVE-2025-23397HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%CVE-2026-2655LOWChaiScript chaiscript_defines.hpp operator use after freeEPSS 0.2%CVE-2022-34391HIGHDell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated maliciouEPSS 0.2%CVE-2024-36292HIGHImproper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authEPSS 0.2%