Falhas do tipo CWE-119

3.289 resultados

Corrupção de Memória Genérica

É uma categoria abrangente que descreve qualquer acesso indevido à memória — escrever fora dos limites de um buffer, ler dados não inicializados, ou manipular ponteiros inválidos. O risco é grave: permite execução de código arbitrário, travamento da aplicação ou exposição de dados sensíveis.

Exemplo

Um programa em C copia dados do usuário para um array sem validar o tamanho (strcpy em vez de strncpy). Um atacante envia uma string maior que o buffer, sobrescrevendo dados adjacentes ou até o endereço de retorno da função, permitindo injetar código malicioso.

Como mitigar

Use funções seguras (strncpy, snprintf, memmove com limites explícitos), valide e sanitize toda entrada antes de copiar, ative canários de pilha e ASLR no SO, e aplique sanitizadores (ASAN, UBSAN) durante desenvolvimento e testes. Em linguagens seguras (Rust, Python) o problema é praticamente eliminado.

CVE-2024-36292HIGHImproper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authEPSS 0.2%CVE-2025-0050MEDIUMMali GPU Userspace Driver allows an Out-of-Bounds accessEPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2026-12330MEDIUMIncorrect boundary conditions in the Internationalization componentEPSS 0.2%CVE-2025-8736MEDIUMGNU cflow Lexer c.c yylex buffer overflowEPSS 0.2%CVE-2023-0202HIGHNVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacEPSS 0.2%CVE-2023-0206HIGHNVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A succEPSS 0.2%CVE-2025-12771HIGHIBM Concert Software Improper Restriction of Operations within the Bounds of a Memory Buffer.EPSS 0.2%CVE-2026-33847HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in linkingvision rapidvmsEPSS 0.2%CVE-2026-1979MEDIUMmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after freeEPSS 0.2%CVE-2026-90826LOWGPAC MP4Box base_scenegraph.c gf_node_del out-of-boundsEPSS 0.2%CVE-2026-2246MEDIUMAprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruptionEPSS 0.2%CVE-2024-44238HIGHThe issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be ableEPSS 0.2%CVE-2026-4012MEDIUMrxi fe fe.c read_ out-of-boundsEPSS 0.2%CVE-2022-32491MEDIUMDell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability bEPSS 0.2%CVE-2026-15194MEDIUMOpen5GS AMF context.c amf_context_final use after freeEPSS 0.2%CVE-2026-91088LOWGPAC URL url.c gf_url_concatenate_ex heap-based overflowEPSS 0.2%CVE-2026-9504MEDIUMGNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-boundsEPSS 0.2%CVE-2026-17512MEDIUMggml-org whisper.cpp log_mel_spectrogram out-of-boundsEPSS 0.2%CVE-2026-9530MEDIUMGNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-boundsEPSS 0.2%